Linux fail2ban Command

Linux 命令大全Complete List of Linux Commands


fail2ban is an open-source intrusion prevention tool used to protect Linux servers from brute-force attacks. It detects malicious behavior, such as multiple failed SSH login attempts, by monitoring system log files (e.g., /var/log/auth.log), and then automatically updates firewall rules to block the IP addresses of these attackers.


fail2ban Core Features

Real-time log monitoring

fail2ban continuously monitors specified log files to look for predefined patterns of malicious behavior.

Automatic IP banning

When multiple failed attempts from the same IP are detected (threshold configurable), fail2ban automatically adds that IP to the firewall block list.

Configurable ban duration

Administrators can set an initial ban time and an incremental ban time after repeated violations.

Multi-service support

It supports not only SSH, but also protection for multiple services such as Apache, Nginx, FTP, and mail services.

Email notification

It can be configured to send email notifications to administrators when an IP is banned.


fail2ban Installation and Configuration

Installation methods

On Debian/Ubuntu-based systems:

Example

sudo apt update
sudo apt install fail2ban

On RHEL/CentOS-based systems:

Example

sudo yum install epel-release
sudo yum install fail2ban

Basic configuration

The main configuration files of fail2ban are located at:

  • /etc/fail2ban/jail.conf- Main configuration file (not recommended to modify directly)
  • /etc/fail2ban/jail.local- User custom configuration (recommended to modify here)

Create a custom configuration file:

sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local

fail2ban Common Commands

Start/Stop/Restart service

Example

sudo systemctl start fail2ban    # Start the service
sudo systemctl stop fail2ban     # Stop the service
sudo systemctl restart fail2ban  # Restart the service
sudo systemctl enable fail2ban   # Enable auto-start on boot

View service status

sudo systemctl status fail2ban

View banned IPs

sudo fail2ban-client status sshd

Unban a specific IP

sudo fail2ban-client set sshd unbanip 192.168.1.100

Manually ban an IP

sudo fail2ban-client set sshd banip 192.168.1.100

fail2ban Configuration File Details

Main configuration parameters

Example

[DEFAULT]
# Ignored IP addresses (whitelist)
ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24

# Ban time (seconds)
bantime = 600

# Detection time window (seconds)
findtime = 600

# Maximum number of attempts
maxretry = 3

# Firewall backend to use
banaction = iptables-multiport

[sshd]
# Whether to enable SSH protection
enabled = true

# Log file path
logpath = %(sshd_log)s

# Filter name
filter = sshd

# Port number
port = ssh

Custom filters

Filters are defined in/etc/fail2ban/filter.d/directory. For example, create a custom SSH filter:

  1. Copy the default SSH filter:

    sudo cp /etc/fail2ban/filter.d/sshd.conf /etc/fail2ban/filter.d/sshd-custom.conf
  2. Edit the custom filter and modify the regular expression to match specific failure patterns.


fail2ban Practical Examples

Protect SSH service

  1. Edit the jail.local file:

    sudo nano /etc/fail2ban/jail.local
  2. Add or modify the following content:

    [sshd]
    enabled = true
    port = ssh
    filter = sshd
    logpath = /var/log/auth.log
    maxretry = 3
    bantime = 3600
    findtime = 600
  3. Restart the fail2ban service:

    sudo systemctl restart fail2ban

Protect Apache service

  1. Make sure jail.local contains the following content:

    [apache]
    enabled = true
    port = http,https
    filter = apache-auth
    logpath = /var/log/apache2/error.log
    maxretry = 3
    bantime = 86400
  2. Restart the service to apply the configuration.


fail2ban Advanced Usage

Using fail2ban to protect custom services

  1. Create a custom filter file:

    sudo nano /etc/fail2ban/filter.d/myapp.conf
  2. Add filter rules (example):

    [Definition]
    failregex = ^.*  .* "POST /login.php.* 401
    ignoreregex =
  3. Add the corresponding jail in jail.local:

    enabled = true
    port = http,https
    filter = myapp
    logpath = /var/log/myapp/access.log
    maxretry = 5
    bantime = 3600

Configure email notifications

  1. Edit the jail.local file:

    [DEFAULT]
    destemail = admin@example.com
    sender = fail2ban@example.com
    mta = sendmail
    action = %(action_mwl)s
  2. Ensure a mail delivery tool (such as sendmail or postfix) is installed and configured on the system.


fail2ban Logs and Troubleshooting

View fail2ban logs

sudo tail -f /var/log/fail2ban.log

Common problem solving

fail2ban is not working

  • Check whether the service is running:sudo systemctl status fail2ban
  • Check the logs for errors:sudo journalctl -u fail2ban

IP not banned

  • Confirm the log path is correct
  • Check whether the filter regular expression matches the log entries
  • Increase log level for debugging: set it in jail.localloglevel = DEBUG

False positive IP ban

  • Add trusted IPs to the ignoreip list
  • Reduce maxretry or increase findtime

fail2ban Best Practices

  1. Update regularly: Keep fail2ban updated to get the latest security fixes and feature improvements.

  2. Reasonable configuration:

    • Set appropriate maxretry and bantime
    • Do not set bantime too long, to avoid banning legitimate users by mistake
    • Do not set it too short either, otherwise the protection effect will be limited
  3. Monitoring and review:

    • Regularly check the banned IP list
    • Analyze logs to understand attack patterns
  4. Multi-layer protection:

    • Combine fail2ban with other security measures (such as firewalls and strong password policies)
    • Consider changing the default SSH port
  5. Backup configuration:

    • Backup custom configuration files and filters
    • Record all modifications for disaster recovery

Summary

fail2ban is an important tool for Linux system security. By automatically detecting and blocking malicious behavior, it effectively prevents brute-force attacks. Correctly configuring and using fail2ban can significantly improve server security while reducing the workload of manual intervention for administrators. Through this article, you should have mastered the basic usage and advanced configuration techniques of fail2ban, and be able to customize your own security protection strategy according to actual needs.


Linux 命令大全Complete List of Linux Commands

Other extensions