---
title: "How To Secure SSH with Fail2Ban"
description: "Stop worrying about brute-force attacks on your server. Learn how Fail2Ban secures SSH on your server in this step-by-step tutorial!"
canonical: "https://adamtheautomator.com/fail2ban-ssh/"
---

# How To Secure SSH with Fail2Ban

> Stop worrying about brute-force attacks on your server. Learn how Fail2Ban secures SSH on your server in this step-by-step tutorial!

Source: https://adamtheautomator.com/fail2ban-ssh/

---

ATA Learning

Tap to hide

[

ATA Learning

](/)

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Search for:  

*   [](https://twitter.com/adbertram)
*   [](https://github.com/Adam-the-Automator)
*   [](https://www.linkedin.com/company/adam-the-automator-llc)
*   [](/feed/)

![How To Secure SSH with Fail2Ban](https://adamtheautomator.com/wp-content/uploads/2021/12/How-To-Secure-SSH-with-Fail2Ban.jpg)

# How To Secure SSH with Fail2Ban

[![](https://secure.gravatar.com/avatar/2788bb1a3f735603f81eca51d68daec56a9d97e805a10268fb2c20afcc76b81b?s=192&d=mm&r=g)Nicholas Xuan Nguyen](https://adamtheautomator.com/author/nicholas-xuan-nguyen/)30 December 20217 min. read

Categories: [IT Ops](/category/it-ops/)

Tags:[Command Line](/tag/command-line/)[Linux](/tag/linux/)[Security](/tag/security/)

Table of Contents

*   [Prerequisites](#prerequisites)
*   [Setting up a Base Firewall](#setting-up-a-base-firewall)
*   [Adjusting your Local Fail2Ban Configuration](#adjusting-your-local-fail2ban-configuration)
*   [Testing your Banning Configurations](#testing-your-banning-configurations)
*   [Conclusion](#conclusion)

Protecting your server from brute force attacks is a must. The question is, how exactly? Lucky for you, [Fail2Ban](https://www.fail2ban.org/wiki/index.php/Main_Page) is just around the corner to protect your server, but Fail2Ban’s default configuration needs some tweaking for optimal security. Worry not though, this tutorial has got you covered.

In this tutorial, you’ll learn how to set up Fail2Ban and ward off brute force attacks by securing your SSH server.

Ready? Read on to optimize security for your SSH server!

## Prerequisites

This tutorial comprises step-by-step instructions. If you’d like to follow along, be sure you have the following in place:

*   An Ubuntu and Debian servers – This tutorial uses a server running [Ubuntu](https://adamtheautomator.com/install-ubuntu/) 18.04 LTS to set up Fail2Ban and a Debian 10 server to test Fail2Ban banning configurations.

Related:[How to Install Ubuntu 20.04 \[Step-by-Step\]](https://adamtheautomator.com/install-ubuntu/)

*   [Root](https://www.ubuntu18.com/ubuntu-enable-root/) access or [sudo](https://www.cyberciti.biz/faq/become-superuser-on-ubuntu-linux/) privileges on the server to execute commands as a superuser.
*   [Fail2Ban installed](https://www.fail2ban.org/wiki/index.php/MANUAL_0_8#Debian) in an Ubuntu or Debian server.

Related:[How to use the Ansible apt Module to Manage Linux Packages](https://adamtheautomator.com/ansible-apt/)

## Setting up a Base Firewall

Fail2Ban protects your server by monitoring the logs and banning IP addresses that make too many login attempts within a certain time frame. But first, you’ll set up a base firewall where you can add rules to block malicious acts on your server.

1\. First, run the `service` command below to stop Fail2Ban (`fail2ban stop`) from running. Stop Fail2Ban when you make changes to your configuration files so that you can test the changes and make sure they work as expected.

```bash
sudo service fail2ban stop
```

![Stopping the fail2ban service](https://adamtheautomator.com/wp-content/uploads/2021/12/image-271.png)

Stopping the fail2ban service

2\. Run the `apt install` command to install [`Sendmail`](https://tecadmin.net/install-sendmail-on-ubuntu/) and [`IPTables-persistent`](https://www.thomas-krenn.com/en/wiki/Saving_Iptables_Firewall_Rules_Permanently#:~:text=Since%20Ubuntu%2010.04%20LTS%20\(Lucid,v6%20for%20IPv6). Sendmail is a program that Fail2Ban uses to notify you when it bans an IP address. While IPTables-persistent is a program that saves your changed configuration settings in the _/etc/sysconfig/iptables_ file.

Having these programs installed keeps your firewall settings intact even if something unexpected happens, like a power outage.

```bash
sudo apt install sendmail iptables-persistent -y
```

Now run each `iptables` command below to set up your firewall. These commands will not generate any output but add four rules to your firewall. These rules either allow or block connections to your server.

```bash
## First Rule - Accepts all traffic generated by the server (lo interface) 
sudo iptables -A INPUT -i lo -j ACCEPT
## Second Rule - Accepts all traffic that are part 
## of an established o related connection
sudo iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
## Third Rule - Allows SSH traffic on port 22
sudo iptables -A INPUT -p tcp --dport 22 -j ACCEPT
## Fourth Rule - Arops all other traffic
sudo iptables -A INPUT -j DROP
```

![Adding four rules to your firewall](https://adamtheautomator.com/wp-content/uploads/2021/12/image-272.png)

Adding four rules to your firewall

4\. Run the `iptables` command below to view a summary of what you have set up in your firewall.

```bash
sudo iptables -S
```

Below, highlighted are the rules that you have added on your firewall.

![Checking your firewall rules](https://adamtheautomator.com/wp-content/uploads/2021/12/image-273.png)

Checking your firewall rules

5\. Next, run the following commands to save your rules in the _/etc/sysconfig/iptables-config_ file and start the Fail2Ban service. The _iptables-config_ file holds all your permanent firewall rules.

Fail2Ban will automatically add a few rules to your firewall to protect your server.

```bash
sudo dpkg-reconfigure iptables-persistent
sudo service fail2ban start
```

6\. Finally, rerun the `iptables` command below to view your firewall rules.

```bash
sudo iptables -S
```

A shown below, highlighted in red are the new rules that Fail2Ban has added to your firewall.

![Previewing your firewall rules](https://adamtheautomator.com/wp-content/uploads/2021/12/image-274.png)

Previewing your firewall rules

## Adjusting your Local Fail2Ban Configuration

Now that you have a basic firewall running, it’s time to adjust your local Fail2Ban configuration file to add more control on securing your server. This tutorial uses the _[/etc/fail2ban/jail.conf](https://serverfault.com/questions/639923/fail2ban-jail-local-vs-jail-conf)_ configuration file as it contains all necessary options to configure global settings for the Fail2Ban application.

Perhaps, you want to create custom rules for your SSH server. If so, you’ll create a new _jail.local_ file (based on the _jail.conf_ file) and put the SSH-specific rules in the _jail.local_ file. Doing so lets you override settings in _jail.conf_ file for your server.

1\. Run the [`awk`](https://linuxize.com/post/awk-command/) command below to perform the following:

*   Print the content (`'{ printf "# "; print; }'`) of the `/etc/fail2ban/jail.conf` file.
*   Create a file named _jail.local_ (based on the _jail.conf_ file), which can use to override the default settings in the _jail.conf_ file.
*   Pipe the content of the `/etc/fail2ban/jail.conf` file to the `tee` command. Doing so will write the `jail.conf` file’s content to your local filesystem (`/etc/fail2ban/jail.local`).

```bash
awk '{ printf "# "; print; }' /etc/fail2ban/jail.conf | sudo tee /etc/fail2ban/jail.local
```

![Creating the jail.local file](https://adamtheautomator.com/wp-content/uploads/2021/12/image-275.png)

Creating the _jail.local_ file

2\. Once you’ve created the _jail.local_ file, run the `ls` command below. The command lists the contents of your server’s Fail2Ban directory (`/etc/fail2ban`) to verify that your _jail.local_ file is generated correctly.

```bash
ls /etc/fail2ban
```

If you see the new **jail.local** file, as shown below, then your local file was generated correctly.

![Checking the newly created local file (jail.local)](https://adamtheautomator.com/wp-content/uploads/2021/12/image-276.png)

Checking the newly created local file (_jail.local_)

3\. Open the _/etc/fail2ban/jail.local_ file in your preferred text editor and navigate to the **\[ssh\]** section.

Uncomment the **\[sshd\]** and **enabled** options by deleting the **#** symbol in front of the options, as shown below to enable SSH.

> _From this point through the rest of the tutorial, remove the **#** symbol in front of either sections or options to enable them._

![Enabling the \[ssh\] section](https://adamtheautomator.com/wp-content/uploads/2021/12/image-277.png)

Enabling the \[ssh\] section

4\. Scroll down, and uncomment the **\[DEFAULT\]** section shown below. This section is where you configure the default settings for Fail2Ban. Any settings in this section will be applied to all [jails](https://docs.plesk.com/en-US/obsidian/administrator-guide/server-administration/protection-against-brute-force-attacks-fail2ban/fail2ban-jails-management.73382/) that Fail2Ban manages.

![Uncommenting the \[DEFAULT\] option](https://adamtheautomator.com/wp-content/uploads/2021/12/image-278.png)

Uncommenting the **\[DEFAULT\]** option

5\. Next, scroll down to the **bantime** section, and set a **bantime** for **60** minutes. The **bantime** option sets the amount of time, in minutes, that an IP address is banned after a failed login attempt.

> _The default bantime setting is 600 seconds (10 minutes). You can adjust this setting to your liking, but it’s important to note that the lower the bantime setting, the more load your server will experience._

![Setting a ban duration](https://adamtheautomator.com/wp-content/uploads/2021/12/image-279.png)

Setting a ban duration

6\. Navigate to the **findtime** and **maxretry** options. Keep the **findtime** as is (**10m**) and lower the **maxretry** to **3**.

The **findtime** option sets the amount of time, in minutes, that an IP address can fail to log in before it gets banned. While the **maxretry** option sets the number of failed login attempts before an IP address is banned.

> _The default **findtime** setting is 10 minutes, and **maxretry** is 5 minutes. As a result, an IP address that fails to log in 5 times within a 10 minute period will be banned._

![Setting a Window Time for an IP Address to Login Before Getting Banned](https://adamtheautomator.com/wp-content/uploads/2021/12/image-280.png)

Setting a Window Time for an IP Address to Login Before Getting Banned

7\. Scroll down, uncomment and configure the **destemail**, **sender**, and **mta** options:

*   **destemail** – Enter an email address where Fail2Ban sends notifications.
*   **sender** – Set the “From” field in the email that Fail2Ban sends to **destemail**.
*   **mta** – Keep the default (**sendmail**) as is. The **mta** option sets the email delivery agent that Fail2Ban uses to send notifications.

![Configuring destemail, sender, and mta options](https://adamtheautomator.com/wp-content/uploads/2021/12/image-281.png)

Configuring destemail, sender, and mta options

8\. Navigate to the **action** options, as shown below, and uncomment the **action\_mwl** option. Doing so lets Fail2Ban send logwatch emails to you. You can review logwatch emails to further investigate any potential security issues on your server.

Save the changes and exit from the text editor.

![Enabling Logwatch Emails](https://adamtheautomator.com/wp-content/uploads/2021/12/image-282.png)

Enabling Logwatch Emails

9\. Now run the commands below to restart your `fail2ban` service.

```bash
sudo service fail2ban stop
sudo service fail2ban start
```

10\. Finally, run the below command to check your `fail2ban` service `status`. `sudo service fail2ban status` If the Fail2Ban service is working, you’ll get an output like the one below.

```bash
sudo service fail2ban status
```

If the Fail2Ban service is working, you’ll get an output like the one below.

![Checking the Fail2Ban Service Status](https://adamtheautomator.com/wp-content/uploads/2021/12/image-283.png)

Checking the Fail2Ban Service Status

## Testing your Banning Configurations

You’ve just configured Fail2Ban, so now it’s time to test if the banning configurations actually work. Attempt multiple failed SSH logins to your Fail2Ban server from a secondary server and see if that secondary server gets banned.

1\. Log in to your secondary server (Debian), and run the below command to SSH into your Fail2Ban server.

This demo uses a Debian 10 server with an IP of 134.122.20.103 to `ssh` to the `fail2ban` server that has an IP of `69.28.83.134`.

```bash
ssh fail2ban@69.28.83.134
```

2\. Enter a random password when prompted and press Enter.

On the first try, the Fail2Ban server will stop the SSH login attempt and print the **Permission denied** message, as shown below. Repeat the SSH login attempt about two to three times more, and the Fail2Ban server will eventually stop responding to your SSH login attempt.

At this point, you won’t get a **Permission denied** message anymore but a blank screen. Getting a blank screen indicates that your second server (Debian) has been banned from the Fail2Ban server.

![Testing if a server gets banned from Fail2Ban server after several failed logins ](https://adamtheautomator.com/wp-content/uploads/2021/12/image-284.png)

Testing if a server gets banned from Fail2Ban server after several failed logins

But perhaps you already have a list of IP address to block from your Fail2Ban server. If so, open the _jail.local_ file and navigate to the **\[DEFAULT\]** section. Uncomment the **ignoreip** option and set the IP addresses to block, as shown below.

> _The address can be either multiple separate IPv4 or IPv6 entries, or else separated by commas._

![Setting IP Addresses to Block from Fail2Ban Server](https://adamtheautomator.com/wp-content/uploads/2021/12/image-285.png)

Setting IP Addresses to Block from Fail2Ban Server

3\. On your Fail2Ban server (Ubuntu), rerun the `iptables` command below to view your firewall rules.

```bash
sudo iptables -S
```

Notice below that there is a new rule that rejects SSH login attempts from the **134.122.20.103** IP address.

You’ll also receive an email from Fail2Ban, upon a successful ban, with a log file attached if you have [sendmail](https://tecadmin.net/install-sendmail-on-ubuntu/) set up on your Fail2Ban server. The email notification indicates that Fail2Ban has successfully stopped a brute-force attack and saved your server from potential damages.

![Checking additional firewall rules](https://adamtheautomator.com/wp-content/uploads/2021/12/image-286.png)

Checking additional firewall rules

## Conclusion

Throughout this tutorial, you’ve learned how to configure Fail2Ban on an Ubuntu server. At this point, you should be well-equipped with the knowledge to protect your SSH server from brute-force attacks.

Now, why not take this newfound knowledge up a notch? Perhaps begin with [blocking IPs on all ports with Fail2Ban on a docker host](https://dev.to/stjernstrom/block-ips-on-all-ports-with-fail2ban-on-a-docker-host-1983)?

Share this article

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fadamtheautomator.com%2Ffail2ban-ssh%2F&text=How%20To%20Secure%20SSH%20with%20Fail2Ban)[Share on Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fadamtheautomator.com%2Ffail2ban-ssh%2F)[Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fadamtheautomator.com%2Ffail2ban-ssh%2F)

## Related Posts

![](https://adamtheautomator.com/wp-content/uploads/2022/01/How-to-Provision-a-Website-With-aaPanel-and-LetsEncrypt.jpg)

### [How to Provision a Website With aaPanel and LetsEncrypt](/aapanel/)

Learn how to install aaPanel, provision a website, and secure the website with SSL using Let’s Encrypt in this step-by-step tutorial!

![](https://adamtheautomator.com/wp-content/uploads/2022/01/How-To-Set-Up-WireGuard-VPN-on-Linux.jpg)

### [How To Set Up WireGuard VPN on Linux](/wireguard-vpn/)

Learn how to set up WireGuard VPN on Linux to securely connect and access your network, in this step-by-step tutorial!

![](https://adamtheautomator.com/wp-content/uploads/2022/01/How-to-Secure-a-Linux-Firewall-With-IPTables-Rules.jpg)

### [How to Secure a Linux Firewall With IPTables Rules](/iptables-rules/)

Secure your vulnerable Ubuntu Linux system with powerful firewall IPTables rules in this step-by-step how-to tutorial!

## Categories

*   [IT Ops](/category/it-ops/)
*   [Cloud](/category/cloud/)
*   [DevOps](/category/devops/)
*   [Home Ops](/category/home-ops/)
*   [Information Security](/category/infosec/)
*   [Software Development](/category/software-development/)

## Site

*   [Home](/)
*   [Tutorials](/tutorials/)
*   [Instructors](/author/)
*   [Advertising](/advertising/)
*   [Recommended Resources](/resources/)
*   [About Adam](/about-adam/)

Copyright 2026© ATA Learning | [Privacy Policy](/privacy/)
