Skip to content

Fail2ban

Fail2ban monitors log files for suspicious activity and bans offending IP addresses.

Configuration

Property Value
Dashboard https://fail2ban.clsxx.de
Control Center https://firewall.clsxx.de (Fail2ban Jails section)
Access VPN-only + BasicAuth
Config /etc/fail2ban/jail.local

Jails

Jail What It Protects Log File Ban Duration
sshd SSH brute force /var/log/auth.log 1 week
traefik-auth BasicAuth failures on web services Traefik access.log 1 week
recidive Repeat offenders (banned by other jails) /var/log/fail2ban.log 1 week

Whitelist

Internal networks are whitelisted and will never be banned:

Network Purpose
127.0.0.1/8 Localhost
10.0.0.0/24 WireGuard strato-host VPN
10.0.1.0/24 WireGuard strato-vm VPN
10.0.3.0/24 WireGuard openclaw-ai VPN
192.168.10.0/24 KVM VM bridge
172.20.10.0/24 Docker openclaw-infra network

Whitelist is configured in /etc/fail2ban/jail.local under [DEFAULT] ignoreip.

How It Works

  1. Fail2ban watches log files for failed authentication attempts
  2. After 5 failures within 10 minutes, the source IP is banned
  3. Banned IPs are blocked via iptables rules
  4. Bans expire after the configured duration (default: 1 week)
  5. Repeat offenders caught by the recidive jail get an additional ban

Management via Control Center

The Control Center (firewall.clsxx.de) provides a Fail2ban management panel:

  • View jails — See all jails with failed/banned/total counts
  • Unban IPs — Click the unban button next to any banned IP
  • Set ban times — Per-jail ban duration selector (1h / 6h / 1d / 1w / 1m / permanent)
  • View whitelist — Shows all whitelisted IPs/networks

API Endpoints

Method Endpoint Description
GET /api/fail2ban/status All jails with banned IPs (live from fail2ban-client)
GET /api/fail2ban/jail/{name} Single jail details
POST /api/fail2ban/unban/{jail}/{ip} Unban an IP
POST /api/fail2ban/bantime/{jail}/{duration} Set ban duration
GET /api/fail2ban/whitelist Whitelisted IPs per jail

Dashboard

The dedicated fail2ban dashboard (fail2ban.clsxx.de) provides:

  • Currently banned IPs with GeoIP data (country, city, ISP)
  • Interactive world map showing attacker locations
  • Ban history and timeline charts
  • Per-jail statistics
  • Live fail2ban log viewer
  • Top attacker rankings
  • Whitelisted IPs display

The dashboard verifies active bans against the runtime state (via Control Center API) rather than relying solely on the fail2ban SQLite database, which can show stale entries for manually unbanned IPs.

Commands

# Check jail status
sudo fail2ban-client status

# Check specific jail
sudo fail2ban-client status sshd

# Unban an IP
sudo fail2ban-client set sshd unbanip <IP>

# Ban an IP manually
sudo fail2ban-client set sshd banip <IP>

# Check whitelist
sudo fail2ban-client get sshd ignoreip