// SSD VPS

How to Install and Configure Fail2Ban on a Linux VPS: Complete Security Guide — CLIQHOST

October 06, 2026 · by Alex M.

How to Install and Configure Fail2Ban on a Linux VPS: Complete Security Guide — CLIQHOST

If you have a SSD VPS or an NVMe VPS exposed to the internet, one of the first threats you will encounter is brute-force attacks: bots trying thousands of username/password combinations against SSH, admin panels, or web forms. Fail2Ban is the classic, lightweight, and highly effective solution that monitors log files and automatically blocks suspicious IPs at the firewall level.

In this guide, you will learn exactly how to install, configure, and customize Fail2Ban on Ubuntu 22.04 / Debian 12, with practical examples for SSH, Nginx, and other services.


What Is Fail2Ban and How Does It Work?

Fail2Ban is a Python daemon that scans log files from services (SSH, Apache, Nginx, FTP, email, etc.) and detects patterns of failed authentication. When the number of failures exceeds a configurable threshold within a defined time window, Fail2Ban automatically adds a rule to iptables (or nftables/ufw) that blocks the attacker's IP for a set period.

Key advantages:

  • Runs in the background without manual intervention
  • Configurable per service (SSH, FTP, HTTP, mail, etc.)
  • Supports custom actions (ban, email alert, webhook)
  • Minimal resource usage — ideal for a 1 vCPU VPS

Prerequisites

Before you begin, make sure you have:

  • A VPS running Ubuntu 22.04 or Debian 12
  • Root access or a user with sudo privileges
  • iptables or ufw installed
  • An active SSH connection

If you don't have a server yet, check the NVMe VPS plans at CLIQHOST — ideal for projects requiring security and speed.


Step 1: Update the System and Install Fail2Ban

Always start with a package update:

sudo apt update && sudo apt upgrade -y

Install Fail2Ban:

sudo apt install fail2ban -y

Verify the service is running:

sudo systemctl status fail2ban

If the service doesn't start automatically:

sudo systemctl enable --now fail2ban

Step 2: Configuration File Structure

Fail2Ban has a flexible configuration architecture:

  • /etc/fail2ban/fail2ban.conf — global daemon configuration
  • /etc/fail2ban/jail.conf — default rules for all "jails"
  • /etc/fail2ban/jail.local — YOUR override file; NEVER modify jail.conf directly!
  • /etc/fail2ban/filter.d/ — predefined filters (regex for logs)
  • /etc/fail2ban/action.d/ — predefined actions (iptables, email, etc.)

The golden rule: make all changes in .local files — package updates can overwrite .conf files.

sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local

Step 3: Basic Configuration in jail.local

Open the file:

sudo nano /etc/fail2ban/jail.local

Locate the [DEFAULT] section and adjust the values:

[DEFAULT]
# IPs or networks that will never be banned
ignoreip = 127.0.0.1/8 ::1 YOUR_HOME_IP

# Ban duration (seconds). 3600 = 1 hour
bantime  = 3600

# Time window for counting attempts (seconds)
findtime = 600

# Max failed attempts before ban
maxretry = 5

# Backend for reading logs
backend = auto

# Default action: ban with iptables
banaction = iptables-multiport

Important: Add your home or office IP to ignoreip so you don't accidentally lock yourself out!


Step 4: Enabling the SSH Jail

SSH is the first target of any bot. Enable protection:

[sshd]
enabled  = true
port     = ssh
logpath  = %(sshd_log)s
backend  = %(sshd_backend)s
maxretry = 3
bantime  = 86400

Here we set bantime = 86400 (24 hours) and maxretry = 3 — stricter than the global defaults. Adjust to fit your needs.

If you changed the SSH port (security best practice):

[sshd]
enabled = true
port    = 2222
logpath = %(sshd_log)s
maxretry = 3
bantime  = 86400

Apply the configuration:

sudo systemctl reload fail2ban

Step 5: Protecting Nginx with Fail2Ban

If you run Nginx on your VPS, you can protect both HTTP authentication attempts and malicious requests.

5.1 Block HTTP Basic Authentication Attempts

[nginx-http-auth]
enabled  = true
port     = http,https
logpath  = /var/log/nginx/error.log
maxretry = 5
bantime  = 3600

5.2 Block Aggressive Scanning (Bad Bots / Scanners)

Create a custom filter:

sudo nano /etc/fail2ban/filter.d/nginx-badbots.conf
[Definition]
failregex = ^<HOST> -.*"(GET|POST|HEAD).*HTTP.*" (400|444|403|408) .*$
ignoreregex =

Add the jail to jail.local:

[nginx-badbots]
enabled  = true
port     = http,https
filter   = nginx-badbots
logpath  = /var/log/nginx/access.log
maxretry = 10
bantime  = 7200
findtime = 300

Step 6: Protecting Postfix / Email Services

Mail servers are frequently targeted. Enable jails for Postfix and Dovecot:

[postfix]
enabled  = true
port     = smtp,465,submission
logpath  = %(postfix_log)s
maxretry = 5

[dovecot]
enabled  = true
port     = pop3,pop3s,imap,imaps,submission,465,sieve
logpath  = %(dovecot_log)s
maxretry = 5
bantime  = 3600

For advanced configurations or if you prefer a managed solution, explore CLIQHOST server management services.


Step 7: Useful Fail2Ban Management Commands

Once configured, you'll frequently use these commands:

Check the status of all jails

sudo fail2ban-client status

Check the status of a specific jail

sudo fail2ban-client status sshd

Typical output:

Status for the jail: sshd
|- Filter
|  |- Currently failed: 2
|  |- Total failed: 47
|  `- Journal matches: ...
`- Actions
   |- Currently banned: 1
   |- Total banned: 8
   `- Banned IP list: 198.51.100.42

Manually unban an IP

sudo fail2ban-client set sshd unbanip 198.51.100.42

Manually ban an IP

sudo fail2ban-client set sshd banip 203.0.113.15

Test a filter before activating it

sudo fail2ban-regex /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf

Step 8: Configuring Email Notifications

Fail2Ban can send an email on each ban — useful for monitoring:

[DEFAULT]
destemail = [email protected]
sender    = [email protected]
mta       = sendmail
action    = %(action_mwl)s

action_mwl = ban + email with relevant logs (whois + log).

Make sure sendmail or another MTA is installed on the server. Alternatively, use an external SMTP relay.


Step 9: Fail2Ban with UFW Instead of iptables

If you use UFW as your firewall (common on Ubuntu), configure Fail2Ban to use it:

[DEFAULT]
banaction = ufw

Make sure UFW is active:

sudo ufw enable
sudo ufw status

Fail2Ban will use the ufw command to add and remove ban rules.


Step 10: Progressive Banning with Recidive

An advanced feature — IPs that are banned multiple times receive increasingly longer bans:

[recidive]
enabled  = true
logpath  = /var/log/fail2ban.log
maxretry = 3
findtime = 86400
bantime  = 604800

This jail monitors the Fail2Ban log itself: if an IP is banned 3 times within 24 hours, it receives a 7-day ban.


Monitoring the Fail2Ban Log

Watch activity in real time:

sudo tail -f /var/log/fail2ban.log

Typical output:

2025-07-01 03:14:22,105 fail2ban.actions [1234]: NOTICE  [sshd] Ban 198.51.100.42
2025-07-01 03:16:01,002 fail2ban.actions [1234]: NOTICE  [sshd] Ban 203.0.113.7

Additional VPS Security Best Practices

Fail2Ban is an important piece of the puzzle, but not the only one. Combine it with:

  1. SSH key authentication — disable password authentication entirely
  2. Changing the SSH port — reduces scanning noise
  3. A strict firewall — allow only the ports you need
  4. Regular updates — keep the system current
  5. SSL certificates for all web-facing services — see CLIQHOST SSL certificates

For enterprise projects or if you'd like to delegate server administration, CLIQHOST managed dedicated servers include proactive monitoring and security hardening.


Common Troubleshooting

Fail2Ban won't start

sudo journalctl -xe -u fail2ban

Check for syntax errors in jail.local.

The filter isn't detecting attacks

Test manually:

sudo fail2ban-regex /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf --print-all-matched

I locked myself out

Access the server via the VNC/KVM console (available in the CLIQHOST control panel) and run:

sudo fail2ban-client set sshd unbanip YOUR_IP

Conclusion

Fail2Ban is an essential tool for any Linux server administrator. With a few dozen minutes of configuration, you dramatically reduce the attack surface of your VPS — at no extra cost and with negligible resource usage.

Key steps recap:

  • Quick installation via apt
  • Configuration in jail.local (not .conf!)
  • Immediate protection for SSH, Nginx, email services
  • Simple commands for monitoring and manual unblocking
  • Advanced features: recidive, email notifications, custom filters

If you're looking for a high-performance, secure Linux VPS to apply this guide, explore the SSD VPS and NVMe VPS options at CLIQHOST — infrastructure in Moldova, real technical support, and transparent pricing. For questions or complex configurations, reach out to our team.

SHARE
// what clients say

What Our Clients Say

Real reviews from customers who trust CLIQHOST for performance, reliability and expert technical support.

★★★★★

"We moved our online shop from a foreign host and the difference is night and day — pages load instantly and support replies in minutes, in Romanian."

AM
Andrei M.
eCommerce owner · Chișinău
★★★★★

"Migrated 12 client sites to CLIQHOST. Free migration, zero downtime, and the cPanel setup is exactly what my team needed. Highly recommend."

EV
Elena V.
Web agency · Bălți
★★★★★

"Our NVMe VPS handles traffic spikes without a sweat. Full root, local datacenter, and billing in MDL — everything we wanted from a provider."

DC
Dmitri C.
SaaS founder · Chișinău