Security

Fail2ban Jail Generator

Generate a fail2ban jail configuration with the right log paths, failure regex, ban times and ignore ranges for SSH, web servers, mail and application logs.

Last reviewed by the Radiatus Cloud team

Configuration appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Rate limiting the log file

Fail2ban watches log files for patterns indicating failed authentication and adds a firewall rule blocking the source address after a threshold is crossed. It does not stop a determined targeted attacker, who has other addresses. What it does very effectively is remove the constant background noise of automated credential stuffing, which on any internet facing SSH port amounts to thousands of attempts a day and which fills logs, wastes CPU on password hashing, and occasionally succeeds against a weak account.

The settings that matter

Three numbers define the policy. maxretry is how many failures trigger a ban. findtime is the window those failures must occur within. bantime is how long the block lasts. The common defaults of five failures in ten minutes with a ten minute ban are far too lenient for the internet: a bot simply waits. Increasing bantime dramatically, or enabling the incremental option so repeat offenders are banned for progressively longer, is where the value is.

Do not lock yourself out

The most common self inflicted incident with fail2ban is banning your own address after a few mistyped passwords or a stale SSH key. Adding your management ranges to ignoreip prevents it, and it must include IPv6 if the host is reachable over IPv6. It is also worth confirming that the backend matches the system: on a host using systemd journal rather than a text log file, a jail configured with logpath silently matches nothing and provides no protection at all while appearing to be enabled.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Which jails should I enable first?

sshd, without question, on any internet facing host. After that, whatever authenticates: web application login endpoints, mail submission, and any admin panel. A jail on a service nobody attacks provides no benefit and adds a way to lock yourself out.

What ban time should I use?

Far longer than the default ten minutes. An hour is a reasonable minimum and a day is common for SSH. Enabling bantime.increment makes repeat offenders escalate automatically, which handles persistent sources without banning first time typos for a week.

Why is my jail enabled but banning nothing?

Usually a backend mismatch. On systemd systems the authentication log may exist only in the journal, so a jail configured with a logpath finds an empty or absent file and matches nothing while reporting itself as active. Set backend to systemd, and check fail2ban-regex against real log lines.

How do I avoid banning myself?

Put your management addresses and ranges in ignoreip, including IPv6 if the host is reachable over it. Test with fail2ban-client status before you need it, and keep console or out of band access available.

Does fail2ban replace other controls?

No. It removes automated noise. Key based SSH authentication with passwords disabled, a firewall restricting management access to known ranges, and multi factor authentication on application logins all do more. Fail2ban is a useful layer on top of those, not a substitute for them.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Choose the services to protect and set your ban policy to generate jail.local and any custom filter.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.