[{"data":1,"prerenderedAt":89},["ShallowReactive",2],{"seo-verification":3,"marketplace-app-en-fail2ban-enhanced":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"slug":7,"name":8,"description":9,"phase":10,"docsUrl":11,"logo":12,"github":13,"tagline":14,"longDescription":15,"features":16,"useCases":23,"steps":33,"faq":46,"specs":59,"compatibleOs":66,"relatedApps":68,"relatedPosts":84,"category":86},"fail2ban-enhanced","Fail2Ban Enhanced","Automatic blocking of intrusion attempts, with a production-optimised configuration and real-time alerts.",1,"https:\u002F\u002Fservorbit.com\u002Fblog\u002Fproteger-vps-fail2ban","https:\u002F\u002Fcdn.jsdelivr.net\u002Fgh\u002Fselfhst\u002Ficons\u002Fpng\u002Ffail2ban.png","https:\u002F\u002Fgithub.com\u002Ffail2ban\u002Ffail2ban","Automatic intrusion blocking — a hardened, production-ready configuration out of the box.","fail2ban watches the logs of your services and automatically bans, through the firewall, the IP addresses that pile up failed authentication attempts. It is the first line of defence — simple and proven — against brute-force attacks on SSH and exposed services.\n\nThis template goes beyond the default install: it deploys a production-hardened configuration (tuned detection windows and ban durations, log reading via systemd, SSH protection enabled from the start). Lightweight and with no web interface, it installs in seconds and protects your server immediately — ideally as a complement to CrowdSec and a hardened bastion.",[17,18,19,20,21,22],"Automatic IP banning after repeated authentication failures","Hardened, production-ready configuration (tuned bantime\u002Ffindtime)","SSH protection enabled from installation","Log reading via systemd (a modern, reliable backend)","Very lightweight — no web interface, minimal memory footprint","Complementary to CrowdSec for defence in depth",[24,27,30],{"title":25,"body":26},"Protect SSH","Automatically block brute-force attacks on the SSH port, the most common target on exposed servers.",{"title":28,"body":29},"Harden a web server","Extend the rules to Nginx or Apache logs to ban scans and exploitation attempts.",{"title":31,"body":32},"Defence in depth","Combine fail2ban (local) with CrowdSec (collaborative) and a hardened bastion for several layers of protection.",[34,37,40,43],{"title":35,"body":36},"Create the VPS","A VPS with 512 MB RAM is enough, Ubuntu 22.04. The template installs fail2ban with a hardened jail.local and SSH protection active.",{"title":38,"body":39},"Check the status","Check with `fail2ban-client status` then `fail2ban-client status sshd`: the SSH jail should be active and watching the logs.",{"title":41,"body":42},"Extend the protections","Enable additional jails (nginx, apache, postfix…) in `\u002Fetc\u002Ffail2ban\u002Fjail.local` according to the services you host.",{"title":44,"body":45},"Tune the thresholds","Adjust `bantime`, `findtime` and `maxretry` to your tolerance, and add your trusted IPs to `ignoreip`.",[47,50,53,56],{"q":48,"a":49},"What is fail2ban?","fail2ban is a security tool that watches logs and automatically bans, through the firewall, the IP addresses responsible for repeated failed authentication attempts.",{"q":51,"a":52},"What does the \"Enhanced\" version add?","A hardened, production-ready configuration: tuned ban durations and detection windows, log reading via systemd, and SSH protection enabled from installation.",{"q":54,"a":55},"Do I have to choose between fail2ban and CrowdSec?","No, they are complementary. fail2ban acts locally and simply; CrowdSec adds collaborative threat intelligence. Many servers run both.",{"q":57,"a":58},"Does fail2ban have a web interface?","No, fail2ban is administered from the command line (`fail2ban-client`). It is a very lightweight service, with no exposed web port.",{"ram":60,"cpu":61,"stack":62},"512 MB","1 vCPU",[63,64,65],"fail2ban","systemd","iptables",[67],"ubuntu-24.04",[69,78],{"name":70,"slug":71,"categorySlug":72,"categoryName":73,"categoryColor":74,"logo":75,"tagline":76,"description":77},"CrowdSec","crowdsec","cybersecurity","Cybersecurity & Bastion","text-red-400 bg-red-500\u002F10","https:\u002F\u002Fcdn.jsdelivr.net\u002Fgh\u002Fselfhst\u002Ficons\u002Fsvg\u002Fcrowdsec.svg","Collaborative protection against attacks — behavioural detection and shared threat intelligence.","Collaborative protection against attacks. Behavioural detection and threat-intelligence sharing with the community.",{"name":79,"slug":80,"categorySlug":72,"categoryName":73,"categoryColor":74,"logo":81,"tagline":82,"description":83},"Bastion Host","bastion-host","\u002Fbrand\u002Flogo\u002Fservorbit-m.svg","A secure, hardened SSH entry point to your infrastructure, with centralised auditing.","A secure entry point to your infrastructure. A configured, hardened SSH jump host with centralised audit logs.",[85],"proteger-vps-fail2ban",{"key":87,"slug":72,"name":73,"objective":88,"icon":87,"color":74},"security","Harden infrastructure security.",1785628468022]