Good afternoon I have the following problem in log maillog, I have many authentication attempts and not fail2ban bans.

Maillog:

Jan 27 14:52:31 cjtterabyte postfix/smtpd[23925]: warning: s15424879.onlinehome-server.com[74.208.9.216]: SASL LOGIN authentication failed: authentication failure
Jan 27 14:52:31 cjtterabyte postfix/smtpd[23925]: lost connection after AUTH from s15424879.onlinehome-server.com[74.208.9.216]
Jan 27 14:52:31 cjtterabyte postfix/smtpd[23925]: disconnect from s15424879.onlinehome-server.com[74.208.9.216]

postfix-sasl.conf:

[INCLUDES]

before = common.conf

[Definition]

_daemon = postfix/smtpd

failregex = ^%(__prefix_line)swarning: [-._\w]+\[<HOST>\]: SASL (?:LOGIN|PLAIN|(?:CRAM|DIGEST)-MD5) authentication failed(: [ A-Za-z0-9+/]*={0,2})?\s*$

# Author: Yaroslav Halchenko

Someone could help me if the filter is well

Regards,
--
Wilmer Arambula. 
Asoc. Cooperativa Tecnologia Terabyte 124, RL.