Fail2ban¶
Fail2ban monitors log files for suspicious activity and bans offending IP addresses.
Configuration¶
| Property | Value |
|---|---|
| Dashboard | https://fail2ban.clsxx.de |
| Control Center | https://firewall.clsxx.de (Fail2ban Jails section) |
| Access | VPN-only + BasicAuth |
| Config | /etc/fail2ban/jail.local |
Jails¶
| Jail | What It Protects | Log File | Ban Duration |
|---|---|---|---|
sshd |
SSH brute force | /var/log/auth.log |
1 week |
traefik-auth |
BasicAuth failures on web services | Traefik access.log | 1 week |
recidive |
Repeat offenders (banned by other jails) | /var/log/fail2ban.log |
1 week |
Whitelist¶
Internal networks are whitelisted and will never be banned:
| Network | Purpose |
|---|---|
127.0.0.1/8 |
Localhost |
10.0.0.0/24 |
WireGuard strato-host VPN |
10.0.1.0/24 |
WireGuard strato-vm VPN |
10.0.3.0/24 |
WireGuard openclaw-ai VPN |
192.168.10.0/24 |
KVM VM bridge |
172.20.10.0/24 |
Docker openclaw-infra network |
Whitelist is configured in /etc/fail2ban/jail.local under [DEFAULT] ignoreip.
How It Works¶
- Fail2ban watches log files for failed authentication attempts
- After 5 failures within 10 minutes, the source IP is banned
- Banned IPs are blocked via iptables rules
- Bans expire after the configured duration (default: 1 week)
- Repeat offenders caught by the
recidivejail get an additional ban
Management via Control Center¶
The Control Center (firewall.clsxx.de) provides a Fail2ban management panel:
- View jails — See all jails with failed/banned/total counts
- Unban IPs — Click the unban button next to any banned IP
- Set ban times — Per-jail ban duration selector (1h / 6h / 1d / 1w / 1m / permanent)
- View whitelist — Shows all whitelisted IPs/networks
API Endpoints¶
| Method | Endpoint | Description |
|---|---|---|
| GET | /api/fail2ban/status |
All jails with banned IPs (live from fail2ban-client) |
| GET | /api/fail2ban/jail/{name} |
Single jail details |
| POST | /api/fail2ban/unban/{jail}/{ip} |
Unban an IP |
| POST | /api/fail2ban/bantime/{jail}/{duration} |
Set ban duration |
| GET | /api/fail2ban/whitelist |
Whitelisted IPs per jail |
Dashboard¶
The dedicated fail2ban dashboard (fail2ban.clsxx.de) provides:
- Currently banned IPs with GeoIP data (country, city, ISP)
- Interactive world map showing attacker locations
- Ban history and timeline charts
- Per-jail statistics
- Live fail2ban log viewer
- Top attacker rankings
- Whitelisted IPs display
The dashboard verifies active bans against the runtime state (via Control Center API) rather than relying solely on the fail2ban SQLite database, which can show stale entries for manually unbanned IPs.