whatis fail2ban
Fail2ban
A daemon that watches logs for repeated failed logins and temporarily bans the offending IP addresses with firewall rules.
What Is Fail2ban in Linux?
Any server with SSH on the internet sees constant brute-force attempts. Fail2ban reads logs or the journal, matches failure patterns with "jails", and adds a firewall block after a threshold, such as five failures in ten minutes.
It reduces noise and load but is not a substitute for key-only SSH authentication. Jails exist for SSH, web servers, mail servers, and many apps.
Example
sudo fail2ban-client status sshd Learn more about Fail2ban
- Fail2Ban Setup Fail2ban monitors log files for repeated authentication failures and automatically bans the offending IP addresses using firewall rules. This guide covers installation, configuration, and managing jails for SSH, nginx, and other services.
- SSH Hardening Guide SSH is the most commonly attacked service on internet-facing Linux servers. This guide covers every important sshd_config setting, key management practices, and tools like fail2ban to reduce your exposure.