Introduction
Fail2ban is a security service that helps protect Linux servers from repeated unsuccessful login attempts and other suspicious activity. It monitors log files for failed authentication attempts and can temporarily ban the IP addresses responsible for those attempts.
In this article, we will explain how to install and configure Fail2ban on a CentOS 7 server and enable protection for SSH login attempts.
Prerequisites
Before proceeding, make sure you have:
- A CentOS 7 server.
- Root or sudo access to the server.
- EPEL repository configured.
- Basic knowledge of Linux commands.
- SSH access to the server.
Implementation
Step 1: Install the EPEL Repository
Fail2ban is available through the EPEL (Extra Packages for Enterprise Linux) repository.
If EPEL is not already installed, install it using:
yum install epel-release
Update the package repository:
yum update
Step 2: Install Fail2ban
Install the Fail2ban package using yum:
yum -y install fail2ban
Step 3: Enable Fail2ban at Boot
Enable the Fail2ban service so that it starts automatically after a server reboot:
systemctl enable fail2ban
Step 4: Configure Fail2ban
Create or edit the jail.local configuration file:
vi /etc/fail2ban/jail.local
Add the following configuration:
[DEFAULT] # Ban hosts for one hour bantime = 3600 # Use iptables for banning banaction = iptables-multiport
[sshd]
enabled = true
In the above configuration:
bantime = 3600blocks an offending IP address for one hour.banactionspecifies the action used to block the IP address.[sshd]enables Fail2ban protection for SSH.enabled = trueactivates the SSH jail.
Step 5: Start Fail2ban
Start the Fail2ban service:
systemctl start fail2ban
You can also verify the service status using:
systemctl status fail2ban
Step 6: Check the Fail2ban Jails
To view the currently configured Fail2ban jails, run:
fail2ban-client status
The output should be similar to:
Status |- Number of jail: 1 `- Jail list: sshd
To get detailed information about the SSH jail, run:
fail2ban-client status sshd
This displays information such as the number of currently banned IP addresses and the total number of failed attempts detected.
Conclusion
In this article, we explained how to install and configure Fail2ban on CentOS 7. We configured Fail2ban to monitor SSH login attempts and temporarily ban IP addresses that make repeated unsuccessful authentication attempts.
Fail2ban provides an additional layer of protection against automated brute-force attacks on services such as SSH.
FAQs
1. What is Fail2ban?
Fail2ban is a security tool that monitors system logs for repeated failed authentication attempts and can temporarily block the associated IP addresses.
2. Where is Fail2ban available on CentOS 7?
Fail2ban is available through the EPEL repository. If EPEL is not installed, install the epel-release package first.
3. How long will an IP address be banned?
In this configuration, the ban time is set to 3600 seconds, which is one hour:
bantime = 3600
4. How can I check whether Fail2ban is running?
Run:
systemctl status fail2ban
Related Article
How to Install and Configure Fail2ban on Ubuntu 18.04 Server – Pheonix Solutions
Install-configure-fail2ban-ubuntu-16-04
Talk to our experts
Have a technology challenge or looking for the right solution for your business? Our team can help you with cloud, DevOps, development, infrastructure, design, and more. Feel free to reach out to our experts here.