Install fail2ban on Ubuntu 24.04, change the ban time and learn to unban yourself. Output from a live server.
A few minutes after a server goes online, strangers start trying to log in over SSH: bots cycle through names like admin, deploy and user. That is normal for any server on the internet. fail2ban reads the log, spots addresses that fail too often and blocks them for a while. Here is how to install it, what it does by default and how not to lock yourself out.
In short. Install it with
sudo apt install fail2ban. On Ubuntu 24.04 SSH protection is on right away: 5 failed attempts in 10 minutes means a 10 minute ban. Check the state withsudo fail2ban-client status sshd. Put your own values into/etc/fail2ban/jail.local, notjail.conf. Add your own address toignoreip. fail2ban does not replace key-based login, it adds to it.
What happens to SSH on a new server
Port 22 is open to everyone, so automatic scanners check it. You can see this in the SSH service log. The command below shows the latest login errors: journalctl reads the system journal, -u ssh keeps only the SSH service and grep picks the lines we need.
sudo journalctl -u ssh --no-pager | grep "Invalid user" | tail -n 5These are the last five such entries on our server:
The addresses change and the names are new every time. Guessing like this is unlikely to succeed, but it floods the log and every attempt costs the server some work. That is where fail2ban comes in. (Addresses and the server name in the output are replaced with sample values.)
Installation
The package is in the standard repository. Refresh the package list first, then install:
sudo apt update && sudo apt install -y fail2banCheck that the service is running and will start after a reboot:
systemctl is-active fail2ban && systemctl is-enabled fail2banThe answer should be active and enabled. To see the version Ubuntu 24.04 installs, run fail2ban-client --version. We got 1.0.2.
What is enabled by default
SSH protection is already configured in a file that ships with the package. Its content:
Line by line. backend = systemd means look for entries in the system journal, not in text files. banaction = nftables means ban with the nftables firewall. [sshd] with enabled = true turns on the jail (fail2ban's name for a set of rules) for SSH. The other values come from jail.conf. Ask the running service for them:
sudo fail2ban-client get sshd maxretrybantime and findtime are read the same way. We got: maxretry = 5 attempts, findtime = 600 seconds (the window in which attempts are counted), bantime = 600 seconds (how long the ban lasts). So 5 errors in 10 minutes closes the address for 10 minutes.
How to see what it caught
A summary of the SSH jail:
sudo fail2ban-client status sshdThis is our server's answer:
Total failed counts failed attempts since the service started, Total banned counts how many addresses were banned. In a little over a day: 706 attempts and 57 bans. Currently banned: 0 means nobody is banned right now: the bans have expired. The history is in fail2ban's own log:
sudo grep NOTICE /var/log/fail2ban.log | tail -n 4The address was banned at 12:11:01 and unbanned at 12:21:01 - exactly 10 minutes. How the address is actually blocked is visible in nftables:
sudo nft list table inet f2b-tableThe rule is simple: packets to port 22 from addresses in the addr-set-sshd set are rejected. fail2ban only adds addresses to this set and removes them.
Your own settings
Better not to edit jail.conf or defaults-debian.conf: a package update may replace them. Put your values into jail.local, which is read later and wins. Open the file:
sudo nano /etc/fail2ban/jail.localAnd add the lines below with your own values. The example bans for an hour after 4 attempts and never touches your own address:
[sshd]bantime = 1hfindtime = 10mmaxretry = 4ignoreip = 127.0.0.1/8 ::1 203.0.113.5Replace 203.0.113.5 with your own permanent address. Each line goes on its own line of the file. Apply the settings:
sudo systemctl restart fail2banIf your address changes, you cannot reliably put it in ignoreip. Then what saves you is key-based login and the fallback through the console (below).
If you banned yourself
Five password typos in a row and your address is closed for the ban time. If you have another way in (a second server or the console), lift the ban like this:
sudo fail2ban-client set sshd unbanip 203.0.113.5If you have no access at all, use the server console: the Weasel panel has a Console tab for each server. The console generally does not connect through the server's port 22, so the ban does not affect it. Inside, run the command above or simply wait out the ban time.
What fail2ban does not do
It does not close a hole, it reduces noise. On our server password login is disabled altogether (PasswordAuthentication no), so none of those 706 attempts could have worked, and the bots tried anyway. The main protection for SSH is key-based login. fail2ban helps when passwords are still on, and it relieves the log and the CPU. If you have not disabled passwords yet, start there and add fail2ban on top. To check your system version and how long it gets updates, see this guide.
FAQ
Do I need fail2ban if I use SSH keys?
Not strictly: passwords are off and guessing gets nowhere. But fail2ban removes the stream of foreign attempts from the log and keeps bots from tying up connections, so it is still worth installing.
How do I list banned addresses?
Run sudo fail2ban-client status sshd. The Banned IP list line shows addresses banned right now. The history is in /var/log/fail2ban.log.
How do I unban an address in fail2ban?
With sudo fail2ban-client set sshd unbanip ADDRESS. To avoid getting banned again, add your address to ignoreip.
Where is the fail2ban config?
In /etc/fail2ban/. Put your values into jail.local and do not edit jail.conf or the files in jail.d that come with the package.
Summary
- Install with
sudo apt install fail2banand checksystemctl is-active fail2ban. - On Ubuntu 24.04 SSH is protected at once: 5 errors in 10 minutes means a 10 minute ban.
- Check the state with
sudo fail2ban-client status sshdand the history in/var/log/fail2ban.log. - Your values go into
/etc/fail2ban/jail.local, your own address intoignoreip. - Unban with
sudo fail2ban-client set sshd unbanip ADDRESS; if you are fully locked out, use the console in the server panel. - Keys matter more than fail2ban: turn off password login first.
