3 ms·
I'm not fond of this writing style without concrete substance; it feels immature. Yes, the author may have tried to be funny, but I don't see a compelling reaso
by dig1 3y ago
I'm not fond of this writing style without concrete substance; it feels immature. Yes, the author may have tried to be funny, but I don't see a compelling reason to stop using fail2ban.
Let's be clear here - fail2ban will not save you if you have a poorly configured SSH server or widely open Nginx/Postfix services, but it will offload traffic blocking to iptables (or whatever firewall you are using). This way, the mentioned services will not have to waste resources just to cancel some connections.
Will it save it against large DDoS? Surely not, but it will stop mild DDoS without problems, which it is designed for. We can argue that iptables/nftables can do a fail2ban job with rate limiting and other techniques many people have never heard of, but if you are at this level, you already know your craft, and I'm pretty sure you considered, tried or used fail2ban before.