← Downloads

Fail2ban 1.1.0

Package v1.1.0 noarch TAR.GZ April 25, 2024

Fail2ban scans log files for repeated authentication failures and bans the offending addresses through nftables, iptables, or another firewall backend.

Download TAR.GZ Project website ↗

Download Mirrors

Mirror Region Download
Fail2ban GitHub Releases Primary Global Download
Fail2ban Home Global Download
Fail2ban Wiki Global Download

Fail2ban watches log files for patterns indicating abuse, most commonly repeated authentication failures, and adds firewall rules blocking the source addresses. Version 1.1.0 is the current stable release and has been for some time; the project is mature and moves slowly, which for this kind of software is appropriate.

Why it is worth running

Any SSH server reachable from the internet receives continuous automated login attempts. Not targeted attacks, just background noise from botnets working through address space.

Fail2ban does not make a well-configured server meaningfully safer against a determined attacker. What it does is stop your logs from being 95% authentication failures, reduce load from the noise, and provide a backstop if something is misconfigured.

Key-only SSH authentication is the actual defence. Fail2ban is the thing you run in addition.

Configuration

Never edit jail.conf. It is overwritten on upgrade. Create jail.local instead, which overrides it.

sudo nano /etc/fail2ban/jail.local
[DEFAULT]
bantime  = 1h
findtime = 10m
maxretry = 5
backend  = systemd
banaction = nftables-multiport

[sshd]
enabled = true

The backend = systemd line matters on modern systems. If your logs go to the journal rather than to files, the default file-watching backend finds nothing and Fail2ban silently does nothing.

Checking it works

sudo systemctl status fail2ban
sudo fail2ban-client status
sudo fail2ban-client status sshd

# Unban an address, for when you lock yourself out
sudo fail2ban-client set sshd unbanip 203.0.113.5

Test your regex against real logs before trusting a custom filter:

fail2ban-regex /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf

Lock yourself out safely

Add your own addresses to ignoreip before you need to:

[DEFAULT]
ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24

Locking yourself out of a remote server with your own intrusion prevention software is a rite of passage and entirely avoidable.

Our Fail2ban setup guide walks through a full configuration, and SSH hardening covers the changes that matter more.

Verify Your Download

Most people should install from their distribution’s repository. Source releases are on GitHub.