Understand the boundary
Fail2ban reads logs and applies temporary blocking actions when configured patterns exceed thresholds. It does not fix vulnerable software, recognise every attack or replace SSH keys. Wrong log selection or an unexpected source address can make a jail ineffective or block your own management connection.
Install from Ubuntu repositories
sudo apt update
sudo apt install fail2banBefore enabling a jail, confirm where SSH authentication events appear. A systemd backend reads the journal; an explicit logpath belongs to a file-based design instead. Check the defaults packaged with your Ubuntu release.
Create a small local override
Use a sudo editor to create /etc/fail2ban/jail.d/sshd.local. For a systemd-journal setup using SSH on port 22:
[sshd]
enabled = true
backend = systemd
port = 22
maxretry = 5
findtime = 10m
bantime = 15mUse the actual SSH port. The blocking action and firewall integration depend on the packaged configuration; inspect them rather than assuming all installations behave identically. If you add ignoreip, restrict it to truly trusted addresses. A large private range is not automatically trusted.
Validate and start
sudo fail2ban-client -t
sudo systemctl restart fail2ban
sudo fail2ban-client status
sudo fail2ban-client status sshdDo not restart after a failed validation. Read the errors and check unit logs. The jail should appear in the status output, but existence alone does not prove it is matching SSH failures.
Test on a controlled route
If you have a separate lab client and console recovery, generate a limited known sequence of failed attempts to a test account. Confirm the failures are counted and the lab source is banned. Do not deliberately ban your only production management address.
An administrator can remove a mistaken ban using the actual source address:
sudo fail2ban-client set sshd unbanip 192.168.50.20Common problems
An empty jail can result from wrong log backend or unmatched messages. A NAT gateway can make many users share a source address. A ban on the wrong port will not protect the real listener. Check the actual firewall action and a functional test, then document the intended behaviour.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.