October 06, 2026 · by Alex M.
If you have a SSD VPS or an NVMe VPS exposed to the internet, one of the first threats you will encounter is brute-force attacks: bots trying thousands of username/password combinations against SSH, admin panels, or web forms. Fail2Ban is the classic, lightweight, and highly effective solution that monitors log files and automatically blocks suspicious IPs at the firewall level.
In this guide, you will learn exactly how to install, configure, and customize Fail2Ban on Ubuntu 22.04 / Debian 12, with practical examples for SSH, Nginx, and other services.
Fail2Ban is a Python daemon that scans log files from services (SSH, Apache, Nginx, FTP, email, etc.) and detects patterns of failed authentication. When the number of failures exceeds a configurable threshold within a defined time window, Fail2Ban automatically adds a rule to iptables (or nftables/ufw) that blocks the attacker's IP for a set period.
Key advantages:
Before you begin, make sure you have:
sudo privilegesiptables or ufw installedIf you don't have a server yet, check the NVMe VPS plans at CLIQHOST — ideal for projects requiring security and speed.
Always start with a package update:
sudo apt update && sudo apt upgrade -y
Install Fail2Ban:
sudo apt install fail2ban -y
Verify the service is running:
sudo systemctl status fail2ban
If the service doesn't start automatically:
sudo systemctl enable --now fail2ban
Fail2Ban has a flexible configuration architecture:
/etc/fail2ban/fail2ban.conf — global daemon configuration/etc/fail2ban/jail.conf — default rules for all "jails"/etc/fail2ban/jail.local — YOUR override file; NEVER modify jail.conf directly!/etc/fail2ban/filter.d/ — predefined filters (regex for logs)/etc/fail2ban/action.d/ — predefined actions (iptables, email, etc.)The golden rule: make all changes in .local files — package updates can overwrite .conf files.
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
Open the file:
sudo nano /etc/fail2ban/jail.local
Locate the [DEFAULT] section and adjust the values:
[DEFAULT]
# IPs or networks that will never be banned
ignoreip = 127.0.0.1/8 ::1 YOUR_HOME_IP
# Ban duration (seconds). 3600 = 1 hour
bantime = 3600
# Time window for counting attempts (seconds)
findtime = 600
# Max failed attempts before ban
maxretry = 5
# Backend for reading logs
backend = auto
# Default action: ban with iptables
banaction = iptables-multiport
Important: Add your home or office IP to
ignoreipso you don't accidentally lock yourself out!
SSH is the first target of any bot. Enable protection:
[sshd]
enabled = true
port = ssh
logpath = %(sshd_log)s
backend = %(sshd_backend)s
maxretry = 3
bantime = 86400
Here we set bantime = 86400 (24 hours) and maxretry = 3 — stricter than the global defaults. Adjust to fit your needs.
If you changed the SSH port (security best practice):
[sshd]
enabled = true
port = 2222
logpath = %(sshd_log)s
maxretry = 3
bantime = 86400
Apply the configuration:
sudo systemctl reload fail2ban
If you run Nginx on your VPS, you can protect both HTTP authentication attempts and malicious requests.
[nginx-http-auth]
enabled = true
port = http,https
logpath = /var/log/nginx/error.log
maxretry = 5
bantime = 3600
Create a custom filter:
sudo nano /etc/fail2ban/filter.d/nginx-badbots.conf
[Definition]
failregex = ^<HOST> -.*"(GET|POST|HEAD).*HTTP.*" (400|444|403|408) .*$
ignoreregex =
Add the jail to jail.local:
[nginx-badbots]
enabled = true
port = http,https
filter = nginx-badbots
logpath = /var/log/nginx/access.log
maxretry = 10
bantime = 7200
findtime = 300
Mail servers are frequently targeted. Enable jails for Postfix and Dovecot:
[postfix]
enabled = true
port = smtp,465,submission
logpath = %(postfix_log)s
maxretry = 5
[dovecot]
enabled = true
port = pop3,pop3s,imap,imaps,submission,465,sieve
logpath = %(dovecot_log)s
maxretry = 5
bantime = 3600
For advanced configurations or if you prefer a managed solution, explore CLIQHOST server management services.
Once configured, you'll frequently use these commands:
sudo fail2ban-client status
sudo fail2ban-client status sshd
Typical output:
Status for the jail: sshd
|- Filter
| |- Currently failed: 2
| |- Total failed: 47
| `- Journal matches: ...
`- Actions
|- Currently banned: 1
|- Total banned: 8
`- Banned IP list: 198.51.100.42
sudo fail2ban-client set sshd unbanip 198.51.100.42
sudo fail2ban-client set sshd banip 203.0.113.15
sudo fail2ban-regex /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf
Fail2Ban can send an email on each ban — useful for monitoring:
[DEFAULT]
destemail = [email protected]
sender = [email protected]
mta = sendmail
action = %(action_mwl)s
action_mwl = ban + email with relevant logs (whois + log).
Make sure sendmail or another MTA is installed on the server. Alternatively, use an external SMTP relay.
If you use UFW as your firewall (common on Ubuntu), configure Fail2Ban to use it:
[DEFAULT]
banaction = ufw
Make sure UFW is active:
sudo ufw enable
sudo ufw status
Fail2Ban will use the ufw command to add and remove ban rules.
An advanced feature — IPs that are banned multiple times receive increasingly longer bans:
[recidive]
enabled = true
logpath = /var/log/fail2ban.log
maxretry = 3
findtime = 86400
bantime = 604800
This jail monitors the Fail2Ban log itself: if an IP is banned 3 times within 24 hours, it receives a 7-day ban.
Watch activity in real time:
sudo tail -f /var/log/fail2ban.log
Typical output:
2025-07-01 03:14:22,105 fail2ban.actions [1234]: NOTICE [sshd] Ban 198.51.100.42
2025-07-01 03:16:01,002 fail2ban.actions [1234]: NOTICE [sshd] Ban 203.0.113.7
Fail2Ban is an important piece of the puzzle, but not the only one. Combine it with:
For enterprise projects or if you'd like to delegate server administration, CLIQHOST managed dedicated servers include proactive monitoring and security hardening.
sudo journalctl -xe -u fail2ban
Check for syntax errors in jail.local.
Test manually:
sudo fail2ban-regex /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf --print-all-matched
Access the server via the VNC/KVM console (available in the CLIQHOST control panel) and run:
sudo fail2ban-client set sshd unbanip YOUR_IP
Fail2Ban is an essential tool for any Linux server administrator. With a few dozen minutes of configuration, you dramatically reduce the attack surface of your VPS — at no extra cost and with negligible resource usage.
Key steps recap:
aptjail.local (not .conf!)If you're looking for a high-performance, secure Linux VPS to apply this guide, explore the SSD VPS and NVMe VPS options at CLIQHOST — infrastructure in Moldova, real technical support, and transparent pricing. For questions or complex configurations, reach out to our team.
Real reviews from customers who trust CLIQHOST for performance, reliability and expert technical support.
"We moved our online shop from a foreign host and the difference is night and day — pages load instantly and support replies in minutes, in Romanian."
"Migrated 12 client sites to CLIQHOST. Free migration, zero downtime, and the cPanel setup is exactly what my team needed. Highly recommend."
"Our NVMe VPS handles traffic spikes without a sweat. Full root, local datacenter, and billing in MDL — everything we wanted from a provider."