Andrew Mercer
on this page

fail2ban reads service logs, and when an address causes too many failures it adds a temporary firewall ban. It works alongside firewalld, iptables, or nftables (nftables / ipset).

Install

sudo dnf -y install fail2ban          # RHEL family (enable EPEL if needed); apt-get install fail2ban on Debian/Ubuntu

Enable the SSH jail

Put local changes in jail.local or jail.d/*.local, not in jail.conf (package updates overwrite the latter).

# /etc/fail2ban/jail.d/sshd.local
[sshd]
enabled  = true
maxretry = 5
findtime = 10m
bantime  = 1h

On firewalld systems, the package ships /etc/fail2ban/jail.d/00-firewalld.conf selecting the firewalld ban action. Keep that in place.

sudo systemctl enable --now fail2ban
sudo systemctl restart fail2ban

Inspect and manage

sudo fail2ban-client status                   # list active jails
sudo fail2ban-client status sshd              # currently banned addresses and counts
sudo fail2ban-client set sshd unbanip 203.0.113.50      # unban (use the jail's name: sshd)
sudo fail2ban-client set sshd banip 203.0.113.51

Never ban yourself: allow-list trusted addresses

# /etc/fail2ban/jail.local
[DEFAULT]
ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24

Fail2ban complements, but doesn't replace, sound SSH hygiene: key-only authentication, no root login, and a reachable-only-when-needed firewall policy.