← Back to all services
Firewalls

Fail2ban Configuration & Setup Guide

fail2ban systemctl: fail2ban

Intrusion prevention - bans IPs with too many failed auth attempts. Works with many services.

🔌 Default Port

N/A
N/A
Monitors logs, uses firewall for bans

📦 Installation Command

apt install fail2ban

⚙️ Configuration Files

  • /etc/fail2ban/jail.conf
  • /etc/fail2ban/jail.local
  • /etc/fail2ban/jail.d/defaults-debian.conf

📂 Default Directories

  • config: /etc/fail2ban
  • data: /var/lib/fail2ban
  • logs: /var/log/fail2ban.log
  • filters: /etc/fail2ban/filter.d
  • actions: /etc/fail2ban/action.d
  • jails: /etc/fail2ban/jail.d

🔐 Default Credentials

Username:N/A
Password:N/A
💡 fail2ban-client requires root

📌 Dependencies

python3iptables or nftables

⚠️ Conflicts

N/A Port: N/A

✅ Works With

sshnginxapache2postfixdovecotasteriskany log-based service

🛡️ Security Notes

Always create jail.local (don't edit jail.conf), whitelist your IP, set appropriate ban times, use incremental banning

❓ Frequently Asked Questions

What does Fail2ban do?
Fail2ban monitors logs and bans IPs showing malicious activity like repeated failed logins.
Where is Fail2ban config?
Config at /etc/fail2ban/jail.conf. Create jail.local for custom settings.
How to unban IP in Fail2ban?
Run: sudo fail2ban-client set <jail> unbanip <IP>