MYTHOSAI

Linux security / PRACTICAL GUIDE

Configure a basic Fail2ban SSH jail on Ubuntu

Reduce repeated SSH authentication attempts while preserving your trusted management route.

Before you start

Ubuntu, sudo, working SSH access and an independent recovery route.

Understand the boundary

Fail2ban reads logs and applies temporary blocking actions when configured patterns exceed thresholds. It does not fix vulnerable software, recognise every attack or replace SSH keys. Wrong log selection or an unexpected source address can make a jail ineffective or block your own management connection.

Install from Ubuntu repositories

bash
sudo apt update
sudo apt install fail2ban

Before enabling a jail, confirm where SSH authentication events appear. A systemd backend reads the journal; an explicit logpath belongs to a file-based design instead. Check the defaults packaged with your Ubuntu release.

Create a small local override

Use a sudo editor to create /etc/fail2ban/jail.d/sshd.local. For a systemd-journal setup using SSH on port 22:

ini
[sshd]
enabled = true
backend = systemd
port = 22
maxretry = 5
findtime = 10m
bantime = 15m

Use the actual SSH port. The blocking action and firewall integration depend on the packaged configuration; inspect them rather than assuming all installations behave identically. If you add ignoreip, restrict it to truly trusted addresses. A large private range is not automatically trusted.

Validate and start

bash
sudo fail2ban-client -t
sudo systemctl restart fail2ban
sudo fail2ban-client status
sudo fail2ban-client status sshd

Do not restart after a failed validation. Read the errors and check unit logs. The jail should appear in the status output, but existence alone does not prove it is matching SSH failures.

Test on a controlled route

If you have a separate lab client and console recovery, generate a limited known sequence of failed attempts to a test account. Confirm the failures are counted and the lab source is banned. Do not deliberately ban your only production management address.

An administrator can remove a mistaken ban using the actual source address:

bash
sudo fail2ban-client set sshd unbanip 192.168.50.20

Common problems

An empty jail can result from wrong log backend or unmatched messages. A NAT gateway can make many users share a source address. A ban on the wrong port will not protect the real listener. Check the actual firewall action and a functional test, then document the intended behaviour.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.