This document describes the Fail2Ban configuration used to protect:
Fail2Ban monitors log files and dynamically bans IP addresses that show malicious behavior (e.g., brute-force attempts, scanning, abuse).
sudo apt update
sudo apt install fail2ban -y
Enable and start the service:
sudo systemctl enable fail2ban
sudo systemctl start fail2ban
Fail2Ban configuration files:
| File | Purpose |
|---|---|
/etc/fail2ban/jail.conf |
Default configuration (DO NOT EDIT) |
/etc/fail2ban/jail.local |
Custom configuration (recommended) |
/etc/fail2ban/filter.d/ |
Filter definitions |
All custom settings are defined in:
/etc/fail2ban/jail.local
[DEFAULT]
bantime = 1h
findtime = 10m
maxretry = 5
backend = systemd
destemail = admin@yourdomain.com
sender = fail2ban@yourdomain.com
action = %(action_mwl)s
| Parameter | Meaning |
|---|---|
bantime |
How long IP is banned |
findtime |
Time window to count failures |
maxretry |
Attempts allowed before ban |
backend |
Log backend (systemd recommended) |
action_mwl |
Ban + send email with logs |
[sshd]
enabled = true
port = 22
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 2h
Protects against:
Since SSH is already restricted to VPN (wg0), this adds an additional defensive layer.
Fail2Ban protects against:
[nginx-http-auth]
enabled = true
filter = nginx-http-auth
port = http,https
logpath = /var/log/nginx/error.log
maxretry = 5
bantime = 1h
Protects against failed HTTP authentication attempts.
[nginx-badbots]
enabled = true
port = http,https
filter = nginx-badbots
logpath = /var/log/nginx/access.log
maxretry = 2
bantime = 4h
Protects against:
[nginx-404]
enabled = true
port = http,https
filter = nginx-404
logpath = /var/log/nginx/access.log
maxretry = 20
findtime = 5m
bantime = 1h
Detects:
Fail2Ban automatically integrates with UFW using:
banaction = ufw
Ensure it is defined in [DEFAULT]:
[DEFAULT]
banaction = ufw
This dynamically inserts firewall rules when banning IPs.
sudo fail2ban-client status
sudo fail2ban-client status sshd
sudo ufw status
sudo systemctl restart fail2ban