Block Automatic SSH Attacks
Requirements
Install fail2ban.
Copy a jail configuration file to make your SSH jail.1
1sudo fail2ban-client status
2cd /etc/fail2ban/
3less jail.conf
4cat << EOF > jail.d/ssh.local
5[sshd]
6enabled = true
7
8ignoreip = 127.0.0.1/8 ::1,192.168.0.0/16 ::1
9EOF
10
11sudo systemctl enable --now fail2ban
12sudo fail2ban-client status
Check the status:
1sudo fail2ban-client status
Watch attacks live:
1fail2ban-client status sshd
-
Check out
man jail.conffor more info. ↩︎