Published on
Takes approximately 1 minute to read
Post HistoryFail2ban Repeat UFW Offenders
The Jail
Fail2Ban is a great project, completely recommended for any public facing server. For the likewise, this is a UFW jail to block repeated UFW offenders.
Create a file /etc/fail2ban/filter.d/ufw-blocked.conf
with:
And update /etc/fail2ban/jail.local
with something like the following:
And make sure fail2ban
gets the new configuration:
Why?
The idea is that anyone port scanning is up to no good, so just block everything (see iptables-allports
) until they go away - might also make the server a bit more stealthy. To be honest, I likely just added this to make the UFW logs less spammy.