Fail2ban can automatically respond to repeated SSH authentication failures by matching events in your logs and running a configured action, commonly a temporary IP ban. To set it up safely, install the package for your Linux distribution, enable the sshd jail in a local override, select the log backend your host actually uses, and verify both the jail and its firewall action. The right settings depend on your distribution, logging setup, and recovery options.
How Fail2ban blocks repeated SSH attempts
Fail2ban monitors service logs for events that match a filter. A jail connects that filter to one or more actions; for SSH, an action may block the source IP after a configured number of matching failures within a time window. The upstream project cautions: “Though Fail2Ban is able to reduce the rate of incorrect authentication attempts, it cannot eliminate the risk presented by weak authentication.” Fail2ban project README
Treat it as one layer of defense, not a replacement for strong SSH authentication. Use public/private key authentication and, where suitable for your environment, two-factor authentication. IP bans can slow repeated attempts from addresses Fail2ban observes; they do not guarantee protection against distributed attempts or account compromise.
How do I set up Fail2ban for SSH?
1. Install the distribution package
Use your Linux distribution’s package manager and follow its service-management instructions. Fail2ban is packaged by many distributions, but package names and commands differ; do not assume one command works everywhere. The project also documents source installation for systems without a suitable package. Fail2ban project README
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
2. Inspect the configuration before adding an override
Look under /etc/fail2ban to see which configuration files and directories your package provides. Keep shipped .conf files unchanged: put local settings in a supported .local file or a supported configuration file in jail.d. This avoids editing distribution defaults that upgrades may replace. Fail2ban upstream jail.conf
The upstream configuration includes an sshd jail, but general jails are disabled by default. Enable the SSH jail explicitly, then check its log source, port and action against your host’s configuration. A minimal illustration is:
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
[sshd]
enabled = true
# Configure the backend and action for this host's logs and firewall.
This is not a complete universal jail: the backend and action are host-specific. Check your installed package’s examples and configuration before restarting. Fail2ban upstream jail.conf
3. Match the backend to SSH’s log source
Choose the approach that matches where your host records SSH authentication events. The systemd backend reads the journal; it uses the jail filter’s journal matching, not logpath. If SSH events are written to a file, use a file-compatible backend and specify the real file path for your distribution. Do not assume /var/log/auth.log exists on every system. Fail2ban upstream jail.conf Ubuntu Jammy jail.conf(5)
Recommended Free Tools
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
| Log-source approach | Use it when | Configuration point |
|---|---|---|
| systemd journal backend | Relevant SSH events are available in the journal and the jail’s journal match is suitable. | Configure the backend and journal matching; do not add logpath. |
| File backend | SSH authentication events are written to a log file. | Use a file-compatible backend and the actual SSH log path on this host. |
Neither approach is universally better; the host’s logging setup and package configuration determine the choice. Fail2ban upstream jail.conf Ubuntu Jammy jail.conf(5)
4. Choose thresholds and an action for your host
maxretry is the number of matching failures that triggers an action within findtime; bantime controls how long an IP remains banned before the unban action. These are policy choices, not universal security settings. Choose them with your legitimate access patterns and a tested emergency recovery route in mind. Time values can use seconds or readable units: Ubuntu’s Jammy manpage documents 600 and 10m as equivalent, with m meaning minutes. That is a format example, not a recommended ban duration. Debian jail.conf(5) Ubuntu Jammy jail.conf(5)
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Do not casually whitelist broad address ranges: an overly broad exception can exempt traffic you intended to protect. Verify the jail’s action files, target SSH port and firewall integration for the firewall stack on this machine; an installed jail alone does not prove that traffic will be blocked. Fail2ban upstream jail.conf Debian jail.conf(5)
5. Start the service and verify the jail
Start or restart Fail2ban using your distribution’s service command. Use fail2ban-client to interact with the running server rather than invoking fail2ban-server directly. First check the installed version, then inspect overall daemon status and the SSH jail; exact command output varies by release. Fail2ban project README
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
fail2ban-client --version
fail2ban-client status
fail2ban-client status sshd
If the daemon or jail does not start, inspect Fail2ban’s own logs and your system journal. Look especially for a missing log source or a backend setting incompatible with the jail. Fail2ban project README Ubuntu Jammy jail.conf(5)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can I check whether Fail2ban is blocking SSH attempts?
Use fail2ban-client status sshd to inspect the SSH jail’s status, including information such as currently banned addresses where reported by your installed version. For a complete check, connect the status back to the host’s configuration: confirm that the jail is active, its filter is reading the intended journal or file, and the configured action matches the SSH port and firewall stack. If expected attempts do not lead to a block, inspect Fail2ban and system logs for parsing, backend or action errors. Command output and available details vary by release. Fail2ban project README Fail2ban upstream jail.conf
Quick Recap
Common setup problems
- The SSH jail is configured but inactive: shipped jails are disabled by default. Enable
[sshd]in your local configuration. Fail2ban upstream jail.conf - No log file or no SSH events appear: check where SSH actually logs. Use the journal backend for journal events; do not combine it with
logpath. For file logs, set a file-compatible backend and the correct path. Fail2ban upstream jail.conf Ubuntu Jammy jail.conf(5) - The jail is active but traffic is not blocked: verify the configured action, destination port and firewall integration instead of assuming the package’s default action is right for your host. Fail2ban upstream jail.conf
- Repeated attempts continue from other addresses: bans apply to addresses Fail2ban observes; they do not stop distributed attempts or replace strong authentication.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

