diff --git a/x-ui.sh b/x-ui.sh index ee49e3665..33ab83f9e 100644 --- a/x-ui.sh +++ b/x-ui.sh @@ -2318,7 +2318,17 @@ setup_fail2ban_iplimit() { centos) if [[ "${VERSION_ID}" =~ ^7 ]]; then yum makecache -y && yum install epel-release -y + # On EL7 fail2ban pulls in firewalld, which is enabled on the + # next boot and blocks every panel/inbound port. The IP Limit + # jail uses raw iptables, so a firewalld that was not there + # before is not needed: keep it from starting on reboot. + rpm -q firewalld &> /dev/null && had_firewalld=1 || had_firewalld=0 yum -y install fail2ban nftables + if [[ "${had_firewalld}" == "0" ]] && rpm -q firewalld &> /dev/null; then + systemctl disable firewalld 2> /dev/null + echo -e "${yellow}firewalld was pulled in by fail2ban and has been disabled so it does not block your ports after a reboot.${plain} +" + fi else dnf makecache -y && dnf -y install fail2ban nftables fi