Fail2ban Custom Jails: Hardening SSH, cPanel & WordPress wp-login on Linux VPS in Pakistan

Protect your Linux VPS and cPanel servers in Pakistan against brute-force attacks and credential stuffing. Complete guide to authoring custom Fail2ban filters and jails for SSH, cPanel WHM, and WordPress.

Fail2ban Custom Jails: Hardening SSH, cPanel & WordPress wp-login on Linux VPS in Pakistan

From automated credential-stuffing botnets scanning standard SSH ports to distributed HTTP floods attacking /wp-login.php and xmlrpc.php, internet-connected servers in Pakistan are under relentless probing. Unprotected servers experience massive CPU and memory spikes simply handling millions of failed authentication attempts, degrading legitimate user traffic and threatening total compromise.

While network-level firewalls filter malicious IP subnets, host-based intrusion prevention is essential for dynamic behavioral blocking. Fail2ban provides this vital defense by scanning real-time system and web service logs, identifying brute-force patterns with regular expressions, and dynamically dropping offending IP addresses via iptables, nftables, or ipset.

In this guide, we walk through configuring Fail2ban on AlmaLinux and Ubuntu, creating custom jails for SSH and cPanel WHM, and stopping WordPress brute-force login attacks dead in their tracks on Cloud VPS and Dedicated Servers.


1. Fail2ban Architecture & Packet Filtering Flow

Fail2ban operates as a lightweight Python daemon that monitors log files, calculates failure rates within a sliding time window (findtime), and triggers kernel-level packet drops when thresholds (maxretry) are violated:

+--------------------------------------------------------------------------+
|                       FAIL2BAN FILTERING PIPELINE                        |
+--------------------------------------------------------------------------+
| Malicious Client ──► Failed Authentication Attempt (SSH / wp-login)      |
|                                │                                         |
|                                ▼                                         |
| [ Application Log Entry: /var/log/auth.log or access.log ]               |
|                                │                                         |
|                                ▼                                         |
| [ Fail2ban Filter (failregex) ]: Matches IP and increments failure count |
|                                │                                         |
|                                ▼ (Failures >= maxretry within findtime)  |
| [ Kernel Action (nftables/iptables) ]: IP blocked via REJECT or DROP     |
|                                │                                         |
|                                ▼                                         |
| Ban Period Elapsed (bantime) ──► Automatic Unban Rule Executed           |
+--------------------------------------------------------------------------+

2. Installation and Baseline Configuration

Step 1: Install Fail2ban

# Ubuntu / Debian
sudo apt-get update
sudo apt-get install -y fail2ban ipset

# AlmaLinux / Rocky Linux (via EPEL repository)
sudo dnf install -y epel-release
sudo dnf install -y fail2ban fail2ban-systemd ipset

Step 2: Create a Persistent jail.local Override

Never modify /etc/fail2ban/jail.conf directly, as upstream package updates will overwrite your customizations. Instead, create /etc/fail2ban/jail.local:

# /etc/fail2ban/jail.local
[DEFAULT]
# Whitelist trusted administrative IP ranges (e.g. your local office / static IP)
ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8

# Ban duration: 1 hour (3600 seconds)
bantime = 1h

# Window to evaluate failed attempts: 10 minutes
findtime = 10m

# Trigger ban after 5 failed attempts
maxretry = 5

# Modern backend for systemd journal scanning
backend = systemd

# Fast kernel-level packet dropping action using iptables/nftables
banaction = iptables-multiport
banaction_allports = iptables-allports

3. Jail 1: Hardened SSH Defense with Port Masking

Even if you have migrated SSH to a custom port, bots will eventually discover it. Configure an aggressive SSH jail in /etc/fail2ban/jail.local:

[sshd]
enabled = true
port = 22,2222
filter = sshd
logpath = %(sshd_log)s
maxretry = 3
findtime = 15m
bantime = 24h

Restart and verify the jail status:

sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshd

4. Jail 2: Mitigating WordPress wp-login.php Brute-Force Attacks

Bots frequently cycle through stolen credentials on WordPress login pages, consuming heavy PHP-FPM processes. We will construct a custom filter and jail to intercept these requests at the web server access log level.

Step 1: Create the Filter Definition

Create /etc/fail2ban/filter.d/wordpress-auth.conf:

# /etc/fail2ban/filter.d/wordpress-auth.conf
[Definition]
# Match POST requests to wp-login.php or xmlrpc.php returning HTTP 200 or 401
failregex = ^<HOST> .* "POST .*(wp-login\.php|xmlrpc\.php).* HTTP/.*" (200|401)
ignoreregex =

Step 2: Configure the WordPress Jail

Append to /etc/fail2ban/jail.local:

[wordpress-auth]
enabled = true
port = http,https
filter = wordpress-auth
logpath = /var/log/nginx/*access.log
          /var/log/apache2/*access.log
          /home/*/access-logs/*
maxretry = 4
findtime = 5m
bantime = 12h
backend = polling

Test your regex filter against live web server logs to ensure zero false positives:

fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/wordpress-auth.conf

5. Jail 3: Securing cPanel & WHM Authentication Daemons (cPhulk Integration)

On cPanel servers, brute-force protection is natively handled by cPHulk. However, combining Fail2ban with cPanel access logs provides instant layer-3 IP packet drops before requests ever hit cPanel’s internal Perl daemons (cpsrvd):

Create /etc/fail2ban/filter.d/cpanel-auth.conf:

# /etc/fail2ban/filter.d/cpanel-auth.conf
[Definition]
failregex = ^\[\S+ \S+\] info \[cpsrvd\] <HOST> - .* authentication failure
ignoreregex =

Add the jail to /etc/fail2ban/jail.local:

[cpanel-auth]
enabled = true
port = 2082,2083,2086,2087,2095,2096
filter = cpanel-auth
logpath = /usr/local/cpanel/logs/login_log
maxretry = 3
findtime = 10m
bantime = 24h

Reload Fail2ban:

sudo fail2ban-client reload

6. Real-Time Operations: Managing Bans and Unbanning IPs

As a sysadmin, you must be able to inspect currently banned IP addresses and release accidental bans for legitimate users:

# Check all active jails
sudo fail2ban-client status

# Inspect specific jail ban list
sudo fail2ban-client status wordpress-auth

# Manually ban an abusive IP address
sudo fail2ban-client set wordpress-auth banip 203.0.113.55

# Unban a legitimate client who forgot their password
sudo fail2ban-client set wordpress-auth unbanip 203.0.113.55

7. Scaling Up Your Infrastructure Defenses

While Fail2ban provides exceptional application-layer filtering on single servers, large-scale multi-gigabit volumetric DDoS attacks require carrier-grade network filtering and dedicated hardware.

Explore our related security and operational guides:

For mission-critical enterprises requiring dedicated unshared networking and bare-metal processing power, deploy on Dedicated Servers in Pakistan.

SERVER SECURITY EXCELLENCE

Deploy Hardened Cloud VPS & Dedicated Servers

Safeguard your web applications with enterprise DDoS mitigation, automated kernel patching, and local low-latency routing across Pakistan.