Motivation
We primarily utilize Fail2Ban to safeguard access to our server through SSH. This tool monitors failed authentication attempts and automatically bans repeat offenders, effectively preventing direct attacks.
Alternatives
DenyHosts and CrowdSec are often cited as good, or even superior, alternatives, but we at Raybeam haven’t particularly tested them.
Install Fail2Ban
Fail2Ban is part of WordOps Stack and can be easily installed with:
wo stack install --fail2ban
You can also install it in Ubuntu with APT:
sudo apt update
sudo apt install fail2ban
Configuring it to send alerts
If not configured properly, Fail2Ban can and will lock you outside of your own VPS. So let’s do every step very carefully. Before enabling it, let’s copy the config file into a new one so we can safely edit it:
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
The default settings are robust enough and WordOps also adds some custom filters on Nginx and wp-login.php, which are good for our use case. Most settings won’t directly affect our own access since we only login via public key. The only configuration we are doing is changing the mode from normal to aggressive on [sshd]:
mode = aggressive
You can optionally configure email notifications so that you receive alerts from the system whenever some IP gets banned:
destemail = yo********@*****le.com
sender = fa***************@*****le.com
mta = sendmail
action = %(action_mw)s
After applying your changes, restart the service:
sudo systemctl restart fail2ban.service
Leave a Reply