install fail2ban ubuntu 10.10

How to install fail2ban on ubuntu 10.10

Install Fail2ban

# apt-get update
# apt-get install fail2ban

List IPtables to see if it is running

# iptables -L

You will see this at bottom of IPTables:

Chain fail2ban-ssh (1 references)
target     prot opt source               destination
RETURN     all  --  anywhere             anywhere

Copy the default .conf file so you can modify it (per the manual you should be editing this file)

# cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local

Update the ignoreip line adding your primary ip address (separate ips with a space)

# "ignoreip" can be an IP address, a CIDR mask or a DNS host
ignoreip =

Add some customizations for apache:

enabled = true
filter = apache-auth
action = iptables[name=ApacheAuth, port=http, protocol=tcp]
sendmail-whois[name=ApacheAuth, [email protected]]
logpath = /var/log/httpd/error_log
maxretry = 6
enabled = true
filter = apache-badbots
action = iptables-multiport[name=BadBots, port="http,https"]
sendmail-buffered[name=BadBots, lines=5, [email protected]]
logpath = /var/log/httpd/access_log
bantime = 172800
maxretry = 3
enabled = true
filter = apache-noscript
action = iptables[name=NoScript, port=http, protocol=tcp]
sendmail-buffered[name=NoScript, lines=5, [email protected]]
logpath = /var/log/httpd/error_log
enabled = true
filter = php-url-fopen
action = iptables[name=php-url-fopen, port=http, protocol=tcp]
sendmail-buffered[name=php-url-fopen, lines=5, [email protected]]
logpath = /var/log/httpd/access_log
maxretry = 1

restart fail2ban

# /etc/init.d/fail2ban restart

Leave a Reply

To create code blocks or other preformatted text, indent by four spaces:

    This will be displayed in a monospaced font. The first four 
    spaces will be stripped off, but all other whitespace
    will be preserved.
    Markdown is turned off in code blocks:
     [This is not a link](

To create not a block, but an inline code span, use backticks:

Here is some inline `code`.

For more help see

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>