Fail2Ban (protection against brute force attacks)
Automatically block IPs that attempt to authenticate repeatedly.
What this tutorial does
The tutorial "Fail2Ban (protection against brute force attacks)" helps you achieve this goal:
Automatically block IPs that attempt to authenticate repeatedly.
Debian/Ubuntu
-
Install Fail2Ban: apt install -y fail2ban - Copy configuration: cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
- Edit /etc/fail2ban/jail.local, section [DEFAULT]:
- bantime = 3600 (ban duration in seconds)
- findtime = 600 (detection window)
- maxretry = 5 (tentatives avant ban)
-
Enable SSH protection in [sshd]: enabled = true - Enable Apache protection in [apache-auth]: enabled = true
-
Start Fail2Ban: systemctl enable --now fail2ban -
See banned IPs: fail2ban-client status sshd -
Unban an IP: fail2ban-client set sshd unbanip 1.2.3.4