Fail2ban watches your server's logs for repeated failed logins and temporarily blocks the offending IP addresses in the firewall. It stops password-guessing bots from hammering SSH and keeps your logs readable.
It is a useful extra layer, not a replacement for SSH keys. Set up key login first if you haven't: How to Set Up SSH Key Login.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
Step 1: Install Fail2ban
Ubuntu and Debian
sudo apt update sudo apt install -y fail2ban python3-systemd
AlmaLinux and Rocky Linux
Fail2ban comes from the EPEL repository. The package includes firewalld integration.
sudo dnf install -y epel-release sudo dnf install -y fail2ban
Step 2: Create your settings file
Never edit jail.conf; updates overwrite it. Put your settings in jail.local instead:
sudo nano /etc/fail2ban/jail.local
Paste this, replacing 198.51.100.7 with your own fixed IP address if you have one (or delete it from the line):
[DEFAULT] # how long an IP stays banned bantime = 1h # the window in which failures are counted findtime = 10m # failures allowed inside that window maxretry = 5 # ban repeat offenders for longer each time bantime.increment = true # never ban these addresses ignoreip = 127.0.0.1/8 ::1 198.51.100.7 [sshd] enabled = true port = ssh backend = systemd [recidive] enabled = true bantime = 1w findtime = 1d
What this does:
- sshd bans an IP after 5 failed SSH logins within 10 minutes.
backend = systemdmakes it read the system journal, which works on all three distributions (Debian 12 no longer writes/var/log/auth.logby default). - bantime.increment doubles the ban for IPs that come back.
- recidive bans IPs for a week if they get banned repeatedly within a day.
If you moved SSH to another port, change port = ssh to port = 2222 (your port).
Step 3: Start and check it
sudo fail2ban-client -t # test the configuration sudo systemctl enable --now fail2ban sudo systemctl restart fail2ban sudo fail2ban-client status sudo fail2ban-client status sshd
The last command shows how many IPs failed and which are currently banned. On a public server, you will usually see the first bans within an hour.
Everyday commands
| Task | Command |
|---|---|
| List active jails | sudo fail2ban-client status |
| Show banned IPs for SSH | sudo fail2ban-client status sshd |
| Unban an IP | sudo fail2ban-client set sshd unbanip 198.51.100.7 |
| Unban everything | sudo fail2ban-client unban --all |
| Watch the log | sudo tail -f /var/log/fail2ban.log |
Protecting websites too
Fail2ban ships with filters for many services. For example, if you use Nginx password-protected folders, add a jail:
[nginx-http-auth] enabled = true port = http,https logpath = /var/log/nginx/error.log
For WordPress login attacks, a security plugin that limits login attempts is usually simpler than a custom Fail2ban filter.
Common problems
- You banned yourself: connect from another network (for example mobile data) and run the unban command, or wait until
bantimeends. Add your IP toignoreipif it is fixed. If you cannot get in at all, use the VPS console. - Fail2ban won't start on Debian with “Have not found any log file for sshd jail”: make sure
backend = systemdis set under[sshd]andpython3-systemdis installed. - No bans ever appear: check
sudo fail2ban-client status sshd. If “Currently failed” stays at 0 while your SSH log shows failures, the port or backend setting is wrong. - Behind Cloudflare: for web jails Fail2ban sees Cloudflare's IPs, not visitors'. Keep web jails off in that case, or restore real visitor IPs in Nginx first.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer