Block Automatic SSH Attacks


Requirements


Install fail2ban.

Copy a jail configuration file to make your SSH jail.1

 1sudo fail2ban-client status
 2cd /etc/fail2ban/
 3less jail.conf
 4cat << EOF > jail.d/ssh.local
 5[sshd]
 6enabled = true
 7
 8ignoreip = 127.0.0.1/8 ::1,192.168.0.0/16 ::1
 9EOF
10
11sudo systemctl enable --now fail2ban
12sudo fail2ban-client status

Check the status:

1sudo fail2ban-client status

Watch attacks live:

1fail2ban-client status sshd

  1. Check out man jail.conf for more info. ↩︎