Installing fail2ban on a VPS to stop SSH password guessing

A server with SSH open receives, day and night, automated password attempts from all over the world. fail2ban reads the logs, spots the addresses that fail too many times and blocks them for a while. It does not replace an SSH key, but it clears the noise and stops anyone who keeps trying. The commands are yours, on your own server: support does not install or repair them (see how far our support goes).

Installing

1 Debian and Ubuntu: sudo apt update and sudo apt install fail2ban.
2 AlmaLinux and Rocky: the package comes from an extra repository: sudo dnf install epel-release and then sudo dnf install fail2ban.
3 Start the service and make it start with the server: sudo systemctl enable --now fail2ban.

Configuring without breaking it

Do not edit /etc/fail2ban/jail.conf: a package update may replace it. Create your own, /etc/fail2ban/jail.local, with only what you want to change:

[DEFAULT]
ignoreip = 127.0.0.1/8 ::1 YOUR.ADDRESS
bantime = 1h
findtime = 10m
maxretry = 5

[sshd]
enabled = true

Line What it does
ignoreip Addresses that are never blocked. Put yours there, so you do not block yourself. Separate them with spaces.
maxretry How many failures, within the findtime window, before blocking. The values in this example (5, 10 minutes, 1 hour) are only a starting point.
findtime The window in which failures are counted.
bantime For how long the address stays blocked.
port If your SSH uses another port, add to [sshd] the line port = 2222, with your number.
1 Restart to apply: sudo systemctl restart fail2ban. You can test the configuration first with sudo fail2ban-client -t.
2 See the overall state: sudo fail2ban-client status lists the active “jails”, which should include sshd.
3 See who is blocked: sudo fail2ban-client status sshd.
4 Unblock an address (yours, if you got it wrong several times): sudo fail2ban-client set sshd unbanip THE.ADDRESS.
You can block yourself. Getting the password wrong five times in a row is enough. Hence ignoreip and an SSH key that works. If it happens, the way back is to come in over another network (mobile data, say) and unblock, or use the panel console: see I have lost SSH access to my server, which has this case as its third cause.
If the SSH log does not exist, fail2ban has nothing to read. On newer systems, which keep logs in the journal, add backend = systemd to the [sshd] section. Where logs live is in where are the logs on a Linux VPS. The firewall does the rest of the work with fail2ban: see setting up the ufw firewall.

Did fail2ban block you and you cannot get in? Tell us the VPS address and where you connect from.

Open a support ticket

SEE ALSO

Setting up the ufw firewall on Ubuntu without locking yourself out

How to create an SSH key and log in without a password

I have lost SSH access to my server

Keeping your VPS or dedicated server secure: the six that matter

RECOMMENDED PRODUCT

VPS server with root access

Resources of your own, the OS you choose, reinstall whenever you like. from $8.40/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?