Security & Hardening · about 2 min · 5 steps
Fail2ban for SSH
Blocks addresses that repeatedly fail to sign in over SSH, for an hour at a time.
Runs on
- Debian / Ubuntu: supported
- RHEL / Fedora: supported — Uses EPEL on RHEL-compatible systems.
- Alpine: supported — Reads sshd messages from the system log (/var/log/messages).
What it changes on your server
- Installs Fail2ban (from EPEL on RHEL-compatible systems) with nftables.
- Adds /etc/fail2ban/jail.d/shellbay-sshd.local: 5 failures in 10 minutes bans an address for 1 hour.
- Never bans this server, the address you're connecting from, or the addresses you list.
What Shellbay asks you
Which addresses should never be banned?
The address you're connecting from now is always allowed. Add other places you sign in from, such as your office network, so a few typos never lock you out. Leave empty if there are none.
- Addresses never to ban (optional)
- Up to 20 IP addresses or ranges
Example:
203.0.113.10, 198.51.100.0/24
Steps
- Prepare packages
- Install Fail2ban
- Protect SSH
- Start Fail2ban and enable it at boot
- Check the SSH jail is active
Shellbay checks the server before the first step, and stops at the first step that fails.
When it's done
- Fail2ban is watching SSH. See bans with sudo fail2ban-client status sshd; lift one with sudo fail2ban-client set sshd unbanip <address>.