From automated credential-stuffing botnets scanning standard SSH ports to distributed HTTP floods attacking /wp-login.php and xmlrpc.php, internet-connected servers in Pakistan are under relentless probing. Unprotected servers experience massive CPU and memory spikes simply handling millions of failed authentication attempts, degrading legitimate user traffic and threatening total compromise.
While network-level firewalls filter malicious IP subnets, host-based intrusion prevention is essential for dynamic behavioral blocking. Fail2ban provides this vital defense by scanning real-time system and web service logs, identifying brute-force patterns with regular expressions, and dynamically dropping offending IP addresses via iptables, nftables, or ipset.
In this guide, we walk through configuring Fail2ban on AlmaLinux and Ubuntu, creating custom jails for SSH and cPanel WHM, and stopping WordPress brute-force login attacks dead in their tracks on Cloud VPS and Dedicated Servers.
1. Fail2ban Architecture & Packet Filtering Flow
Fail2ban operates as a lightweight Python daemon that monitors log files, calculates failure rates within a sliding time window (findtime), and triggers kernel-level packet drops when thresholds (maxretry) are violated:
+--------------------------------------------------------------------------+
| FAIL2BAN FILTERING PIPELINE |
+--------------------------------------------------------------------------+
| Malicious Client ──► Failed Authentication Attempt (SSH / wp-login) |
| │ |
| ▼ |
| [ Application Log Entry: /var/log/auth.log or access.log ] |
| │ |
| ▼ |
| [ Fail2ban Filter (failregex) ]: Matches IP and increments failure count |
| │ |
| ▼ (Failures >= maxretry within findtime) |
| [ Kernel Action (nftables/iptables) ]: IP blocked via REJECT or DROP |
| │ |
| ▼ |
| Ban Period Elapsed (bantime) ──► Automatic Unban Rule Executed |
+--------------------------------------------------------------------------+
2. Installation and Baseline Configuration
Step 1: Install Fail2ban
# Ubuntu / Debian
sudo apt-get update
sudo apt-get install -y fail2ban ipset
# AlmaLinux / Rocky Linux (via EPEL repository)
sudo dnf install -y epel-release
sudo dnf install -y fail2ban fail2ban-systemd ipset
Step 2: Create a Persistent jail.local Override
Never modify /etc/fail2ban/jail.conf directly, as upstream package updates will overwrite your customizations. Instead, create /etc/fail2ban/jail.local:
# /etc/fail2ban/jail.local
[DEFAULT]
# Whitelist trusted administrative IP ranges (e.g. your local office / static IP)
ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8
# Ban duration: 1 hour (3600 seconds)
bantime = 1h
# Window to evaluate failed attempts: 10 minutes
findtime = 10m
# Trigger ban after 5 failed attempts
maxretry = 5
# Modern backend for systemd journal scanning
backend = systemd
# Fast kernel-level packet dropping action using iptables/nftables
banaction = iptables-multiport
banaction_allports = iptables-allports
3. Jail 1: Hardened SSH Defense with Port Masking
Even if you have migrated SSH to a custom port, bots will eventually discover it. Configure an aggressive SSH jail in /etc/fail2ban/jail.local:
[sshd]
enabled = true
port = 22,2222
filter = sshd
logpath = %(sshd_log)s
maxretry = 3
findtime = 15m
bantime = 24h
Restart and verify the jail status:
sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshd
4. Jail 2: Mitigating WordPress wp-login.php Brute-Force Attacks
Bots frequently cycle through stolen credentials on WordPress login pages, consuming heavy PHP-FPM processes. We will construct a custom filter and jail to intercept these requests at the web server access log level.
Step 1: Create the Filter Definition
Create /etc/fail2ban/filter.d/wordpress-auth.conf:
# /etc/fail2ban/filter.d/wordpress-auth.conf
[Definition]
# Match POST requests to wp-login.php or xmlrpc.php returning HTTP 200 or 401
failregex = ^<HOST> .* "POST .*(wp-login\.php|xmlrpc\.php).* HTTP/.*" (200|401)
ignoreregex =
Step 2: Configure the WordPress Jail
Append to /etc/fail2ban/jail.local:
[wordpress-auth]
enabled = true
port = http,https
filter = wordpress-auth
logpath = /var/log/nginx/*access.log
/var/log/apache2/*access.log
/home/*/access-logs/*
maxretry = 4
findtime = 5m
bantime = 12h
backend = polling
Test your regex filter against live web server logs to ensure zero false positives:
fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/wordpress-auth.conf
5. Jail 3: Securing cPanel & WHM Authentication Daemons (cPhulk Integration)
On cPanel servers, brute-force protection is natively handled by cPHulk. However, combining Fail2ban with cPanel access logs provides instant layer-3 IP packet drops before requests ever hit cPanel’s internal Perl daemons (cpsrvd):
Create /etc/fail2ban/filter.d/cpanel-auth.conf:
# /etc/fail2ban/filter.d/cpanel-auth.conf
[Definition]
failregex = ^\[\S+ \S+\] info \[cpsrvd\] <HOST> - .* authentication failure
ignoreregex =
Add the jail to /etc/fail2ban/jail.local:
[cpanel-auth]
enabled = true
port = 2082,2083,2086,2087,2095,2096
filter = cpanel-auth
logpath = /usr/local/cpanel/logs/login_log
maxretry = 3
findtime = 10m
bantime = 24h
Reload Fail2ban:
sudo fail2ban-client reload
6. Real-Time Operations: Managing Bans and Unbanning IPs
As a sysadmin, you must be able to inspect currently banned IP addresses and release accidental bans for legitimate users:
# Check all active jails
sudo fail2ban-client status
# Inspect specific jail ban list
sudo fail2ban-client status wordpress-auth
# Manually ban an abusive IP address
sudo fail2ban-client set wordpress-auth banip 203.0.113.55
# Unban a legitimate client who forgot their password
sudo fail2ban-client set wordpress-auth unbanip 203.0.113.55
7. Scaling Up Your Infrastructure Defenses
While Fail2ban provides exceptional application-layer filtering on single servers, large-scale multi-gigabit volumetric DDoS attacks require carrier-grade network filtering and dedicated hardware.
Explore our related security and operational guides:
- Docker Firewall Hardening with iptables and UFW on Linux VPS
- CSF Firewall Hardening for cPanel and WHM
- Linux VPS Swap Tuning & zRAM Optimization
For mission-critical enterprises requiring dedicated unshared networking and bare-metal processing power, deploy on Dedicated Servers in Pakistan.
Deploy Hardened Cloud VPS & Dedicated Servers
Safeguard your web applications with enterprise DDoS mitigation, automated kernel patching, and local low-latency routing across Pakistan.
