Current features (0.8.x)
Here is a list of the main features available in Fail2ban.
- Client/Server architecture.
- Highly configurable.
- FAM/Gamin/Pyinotify support.
- Parses log files and looks for given patterns.
- Executes commands when a pattern has been detected for the same IP address for more than X times. X can be changed.
- After a given amount of time, executes another command in order to unban the IP address.
- Uses Netfilter/Iptables by default but can also use TCP Wrapper (/etc/hosts.deny) and many other firewalls/actions.
- Handles log files rotation.
- Can handle multiple service (sshd, apache, vsftpd, etc).
- Resolves DNS hostname to IP address (use with caution, disable by usedns = no).
Please browse Fail2ban milestones for an up-to-date list of planned releases/features.
Below are some items from older roadmap
- Add more tags (<LINE>, <USER>, <PORT>) Partially done -- use <MATCHES>. Also see Issue #10 and Issue #67
- Add support for pyinotify
- Auto-enable feature (activate jail if log file is present)
- Manual control of ban list (ban, unban, reset). Partially done Issue #53 . You currently have to restart the daemon to unban.
- There's a patch by Buanzo that adds a 'banip' command to fail2ban-client.
Other envisioned changes
- Decrease memory usage
- Multi-lines parsing