Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

Why install fail2ban? You already have SSH password auth disabled, and you only allow SSH connections from your office. Won't this just risk banning your own office if someone's SSH client is misconfigured?


If helps if a) you've misconfigured your "office only" rules, or b) someone has breached your office network/one of your local machines (but hasn't discovered any of your keys/passwords yet) and is trying to get into the server. It also helps with non-ssh services too. A belt-and-braces approach. If you accidentally lock yourself out using it, use your out-of-band access to re-enable your logins.


fail2ban is useful for things other than SSH - I've seen it deal handily with people probing our asterisk server.


agreed, you can set up fancy jails for people scanning other services too, someone who probes SMTP/POP/IMAP doesn't need to hit SIP and SSH. Depending on the scenario you could choose to say block an entire netblock from hitting ssh after a single offensive IP probes a few services. Even a 10min jail time will cause most attackers to give up and move along to their next victim (unless you're being targeted.)


Seconded.

Autobanning always causes trouble if enough people use the server from one IP address.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: