4 ms·
Is fail2ban obscure? I was under the impression it was a must have for any server exposed to the internet.
by exciteabletom 5y ago
Is fail2ban obscure? I was under the impression it was a must have for any server exposed to the internet.
- deleted 5y ago[deleted]
- invokestatic 5y agoMy thinking is that good security configuration makes fail2ban redundant. With password authentication disabled and strong keys, it’s not clear to me what the threat is that fail2ban offers to protect against.
- deng 5y agoI use it mostly because it simply declutters the logfiles, and it's super easy to set up and has practically no maintenance, so why not? EDIT: as others have noted here, fail2ban can do much more than just ssh. I also use it for Exim to block all these open-relay-scanners which are polluting the logs.
- forty 5y agoNo maintenance except the security patches I guess :)
- ponyous 5y agofail2ban is not only for SSH, but also for HTTP. You have a php website with apache and logs enabled? Fail2ban can ban people if they try to brute force your login page. It's actually quite powerful, but I see it in use less and less.
- zikduruqe 5y agoThis. I host a very simple website at home on my Raspberry Pi; maybe 20 regular users. But, I receive a ton of traffic trying to login to PHP admin, nginx scripts, ssh brute force attempts, and on and on... I use fail2ban to ban individual IPs and if I see a lot coming from a particular CIDR range, I'll just block that whole range. There are a ton of example jails out on GitHub and elsewhere that are easily dropped into your configs.
- api 5y agoWhy is it a must have? Just disable password logins on Internet-facing systems.
- exciteabletom 5y agoI should have been more explicit, you're right it's not necessary for SSH with keys. I was thinking more about preventing spam on web servers.
- _flux 5y agoI like to use it just to make logs more readable.
- cuspycode 5y agoI use it for ssh, ftp, and dovecot. Even with ssh passwords disabled, fail2ban reduces traffic a lot on some servers (since culprits get null-routed) which is always good.
- varjag 5y agoIt's great for HTTP as well. If there's something 404ing on your backend there's no reason not to ban it.
- staysafeanon 5y agoThis is why we enable port knocking (SPA) on all of our Internet-facing systems: it protects against zero-days and keeps the logs pristine. As a matter fact, any failed login of any kind creates a security alert.
- snvzz 5y agoThere's less ducktape solutions such as sshguard.
- mrweasel 5y agoI mostly see it on smaller systems configured by people or teams who doesn't really manage servers professionally. Mostly we just don't allow SSH via the internet, you have to be on the office network or on a VPN and AWS instances can be accessed using Amazon Systems Manager. For those few systems that absolutely most be accessible via SSH on the internet: SSH keys and/or multi-factor authentication is required.