Fail2ban
Fail2ban scans log files (e.g. /var/log/apache/error_log) and bans IPs that show the malicious signs -- too many password failures, seeking for exploits, etc. Generally Fail2Ban is then used to update firewall rules to reject the IP addresses for a specified amount of time, although any arbitrary other action (e.g. sending an email) could also be configured. Out of the box Fail2Ban comes with filters for various services (apache, courier, ssh, etc).

Fail2Ban is able to reduce the rate of incorrect authentications attempts however it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services.


ChangeLog (List of changes)
Requirements (Needed requirements for Fail2ban)
Features (List of current and planned features)
Issues (Bugtracker)
Screenshots (Screenshots)
Downloads (Fail2ban for your distribution)
Presentations (Past presentations (slides, videos))
Links (Links related to Fail2ban)
Mailing list (Support and discussions)
HOWTO Seek Help


README (Official README file)
Manual (Official Fail2ban documentation)
Configuration (Configuration related to external software)
FAQ (Frequently Asked Questions)
HOWTOs (HOWTOs contributed by users)
Reference Manual (Source code documentation)
Proposed documentation for Hostname vs. IP Address Logging


Contributors (persons who contributed to the project)
Get Involved


2014/10/28 0.9.1 is a big bugfix and new functionality release. Release Notes for 0.9.1.

2014/08/19 0.8.14 is a minor bugfix release primarily to fix Python 2.4 compatibility. Release Notes for 0.8.14.

2014/03/15 0.9.0 is out. Added database and major improvements to filter and action capabilities Release Notes for 0.9.0.

2014/03/15 0.8.13 is a minor release on 0.8.12 to correct filters, actions and improve some error handling in core. Release Notes for 0.8.13.

2014/01/2 0.8.12 is out. Added features flushlogs for improved log rotation and ignorecommand for dynamic ignores. Fixed apache filters that where over tightened last release and added some new filters. For more details see the release notes

Latest versions

gamma  : fail2ban-0.9.1
stable  : fail2ban-0.8.14
dont-wanna-be-released-ever-again -- 0.8.x fixes  : GIT 0.8 branch
wanna-be-stable -- 0.9.x fixes  : GIT master branch

