Welcome to Configuring Fail2Ban to Prevent SSH Brute-Force Attacks on Cloud Servers. The moment you spin up a new VPS with a public IP address, automated bots begin trying to brute-force their way into your SSH port. Fail2Ban is your first line of automated defense.
1. Understanding Fail2Ban
Fail2Ban is an intrusion prevention software framework that protects computer servers from brute-force attacks. It works by monitoring log files (like /var/log/auth.log or /var/log/secure) for patterns of malicious activity, such as repeated failed login attempts, and automatically updating firewall rules to block the offending IP addresses.
2. Installing Fail2Ban
Installation is straightforward. On Debian/Ubuntu systems, simply run sudo apt install fail2ban. On RHEL/CentOS systems, ensure the EPEL repository is enabled, then run sudo yum install fail2ban. Once installed, the service automatically starts and enables basic SSH protection.
3. Creating a Local Configuration
Never modify the default jail.conf file, as package updates will overwrite your changes. Instead, create a copy named jail.local (e.g., sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local). Fail2Ban reads the .local file last, meaning any settings defined here override the defaults.
4. Tuning the SSH Jail
Open jail.local and locate the [sshd] section. You can customize the ban threshold and duration. For example, setting bantime = 1h, findtime = 10m, and maxretry = 3 means if an IP fails to log in 3 times within 10 minutes, it will be banned for 1 hour.
5. Implementing Progressive Banning
Advanced administrators can configure "recidive" jails. If a bot IP is repeatedly banned and unbanned over a period of weeks, the recidive jail tracks these recurring bans and applies a much longer, permanent, or multi-week ban to persistent offenders.
Conclusion
Coupled with disabling password authentication and using SSH keys, Fail2Ban ensures your server's access points remain secure without requiring constant manual log monitoring.