fail2ban reads service logs, and when an address causes too many failures it adds a temporary firewall ban. It works alongside firewalld, iptables, or nftables (nftables / ipset).
Install¶
sudo dnf -y install fail2ban # RHEL family (enable EPEL if needed); apt-get install fail2ban on Debian/Ubuntu
Enable the SSH jail¶
Put local changes in jail.local or jail.d/*.local, not in jail.conf (package updates overwrite the latter).
# /etc/fail2ban/jail.d/sshd.local
[sshd]
enabled = true
maxretry = 5
findtime = 10m
bantime = 1h
On firewalld systems, the package ships /etc/fail2ban/jail.d/00-firewalld.conf selecting the firewalld ban action. Keep that in place.
sudo systemctl enable --now fail2ban
sudo systemctl restart fail2ban
Inspect and manage¶
sudo fail2ban-client status # list active jails
sudo fail2ban-client status sshd # currently banned addresses and counts
sudo fail2ban-client set sshd unbanip 203.0.113.50 # unban (use the jail's name: sshd)
sudo fail2ban-client set sshd banip 203.0.113.51
Never ban yourself: allow-list trusted addresses¶
# /etc/fail2ban/jail.local
[DEFAULT]
ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24
Fail2ban complements, but doesn't replace, sound SSH hygiene: key-only authentication, no root login, and a reachable-only-when-needed firewall policy.