Linux fail2ban Command
Complete List of Linux Commands
fail2ban is an open-source intrusion prevention tool used to protect Linux servers from brute-force attacks. It detects malicious behavior, such as multiple failed SSH login attempts, by monitoring system log files (e.g., /var/log/auth.log), and then automatically updates firewall rules to block the IP addresses of these attackers.
fail2ban Core Features
Real-time log monitoring
fail2ban continuously monitors specified log files to look for predefined patterns of malicious behavior.
Automatic IP banning
When multiple failed attempts from the same IP are detected (threshold configurable), fail2ban automatically adds that IP to the firewall block list.
Configurable ban duration
Administrators can set an initial ban time and an incremental ban time after repeated violations.
Multi-service support
It supports not only SSH, but also protection for multiple services such as Apache, Nginx, FTP, and mail services.
Email notification
It can be configured to send email notifications to administrators when an IP is banned.
fail2ban Installation and Configuration
Installation methods
On Debian/Ubuntu-based systems:
Example
sudo apt install fail2ban
On RHEL/CentOS-based systems:
Example
sudo yum install fail2ban
Basic configuration
The main configuration files of fail2ban are located at:
/etc/fail2ban/jail.conf- Main configuration file (not recommended to modify directly)/etc/fail2ban/jail.local- User custom configuration (recommended to modify here)
Create a custom configuration file:
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
fail2ban Common Commands
Start/Stop/Restart service
Example
sudo systemctl stop fail2ban # Stop the service
sudo systemctl restart fail2ban # Restart the service
sudo systemctl enable fail2ban # Enable auto-start on boot
View service status
sudo systemctl status fail2ban
View banned IPs
sudo fail2ban-client status sshd
Unban a specific IP
sudo fail2ban-client set sshd unbanip 192.168.1.100
Manually ban an IP
sudo fail2ban-client set sshd banip 192.168.1.100
fail2ban Configuration File Details
Main configuration parameters
Example
# Ignored IP addresses (whitelist)
ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24
# Ban time (seconds)
bantime = 600
# Detection time window (seconds)
findtime = 600
# Maximum number of attempts
maxretry = 3
# Firewall backend to use
banaction = iptables-multiport
[sshd]
# Whether to enable SSH protection
enabled = true
# Log file path
logpath = %(sshd_log)s
# Filter name
filter = sshd
# Port number
port = ssh
Custom filters
Filters are defined in/etc/fail2ban/filter.d/directory. For example, create a custom SSH filter:
-
Copy the default SSH filter:
sudo cp /etc/fail2ban/filter.d/sshd.conf /etc/fail2ban/filter.d/sshd-custom.conf
-
Edit the custom filter and modify the regular expression to match specific failure patterns.
fail2ban Practical Examples
Protect SSH service
-
Edit the jail.local file:
sudo nano /etc/fail2ban/jail.local
-
Add or modify the following content:
[sshd] enabled = true port = ssh filter = sshd logpath = /var/log/auth.log maxretry = 3 bantime = 3600 findtime = 600
-
Restart the fail2ban service:
sudo systemctl restart fail2ban
Protect Apache service
-
Make sure jail.local contains the following content:
[apache] enabled = true port = http,https filter = apache-auth logpath = /var/log/apache2/error.log maxretry = 3 bantime = 86400
-
Restart the service to apply the configuration.
fail2ban Advanced Usage
Using fail2ban to protect custom services
-
Create a custom filter file:
sudo nano /etc/fail2ban/filter.d/myapp.conf
-
Add filter rules (example):
[Definition] failregex = ^.* .* "POST /login.php.* 401 ignoreregex =
-
Add the corresponding jail in jail.local:
enabled = true port = http,https filter = myapp logpath = /var/log/myapp/access.log maxretry = 5 bantime = 3600
Configure email notifications
-
Edit the jail.local file:
[DEFAULT] destemail = admin@example.com sender = fail2ban@example.com mta = sendmail action = %(action_mwl)s
-
Ensure a mail delivery tool (such as sendmail or postfix) is installed and configured on the system.
fail2ban Logs and Troubleshooting
View fail2ban logs
sudo tail -f /var/log/fail2ban.log
Common problem solving
fail2ban is not working
- Check whether the service is running:
sudo systemctl status fail2ban - Check the logs for errors:
sudo journalctl -u fail2ban
IP not banned
- Confirm the log path is correct
- Check whether the filter regular expression matches the log entries
- Increase log level for debugging: set it in jail.local
loglevel = DEBUG
False positive IP ban
- Add trusted IPs to the ignoreip list
- Reduce maxretry or increase findtime
fail2ban Best Practices
-
Update regularly: Keep fail2ban updated to get the latest security fixes and feature improvements.
-
Reasonable configuration:
- Set appropriate maxretry and bantime
- Do not set bantime too long, to avoid banning legitimate users by mistake
- Do not set it too short either, otherwise the protection effect will be limited
-
Monitoring and review:
- Regularly check the banned IP list
- Analyze logs to understand attack patterns
-
Multi-layer protection:
- Combine fail2ban with other security measures (such as firewalls and strong password policies)
- Consider changing the default SSH port
-
Backup configuration:
- Backup custom configuration files and filters
- Record all modifications for disaster recovery
Summary
fail2ban is an important tool for Linux system security. By automatically detecting and blocking malicious behavior, it effectively prevents brute-force attacks. Correctly configuring and using fail2ban can significantly improve server security while reducing the workload of manual intervention for administrators. Through this article, you should have mastered the basic usage and advanced configuration techniques of fail2ban, and be able to customize your own security protection strategy according to actual needs.
Other extensions