---
title: "How to set up Fail2Ban on a VPS: SSH, Nginx and repeat offenders | StreetHosting"
description: "Install Fail2Ban on Ubuntu, create jail.local and enable jails for SSH, Nginx and repeat offenders, with the right backend on 24.04, ban queries and unban."
url: "https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup"
type: "page"
language: "en-US"
---

VPS · 8 min · Intermediate

Published on Jun 17, 2026 · Updated on Sep 28, 2026

# Fail2Ban on an Ubuntu VPS: jails for SSH, Nginx and repeat offenders

Fail2Ban reads your logs, spots the IPs that fail too often and bans them in the firewall. Learn how to set it up on Ubuntu 24.04, where the package defaults change how jails behave, and how to manage bans day to day.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Security and hardening](https://streethosting.com.br/en/guides/topics/security) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20set%20up%20Fail2Ban%20on%20a%20VPS%3A%20SSH%2C%20Nginx%20and%20repeat%20offenders&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup "Share on LinkedIn") [](https://wa.me/?text=How%20to%20set%20up%20Fail2Ban%20on%20a%20VPS%3A%20SSH%2C%20Nginx%20and%20repeat%20offenders%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Ffail2ban-ssh-vps-setup "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup.md)

In this guide 8 sections

* [What Fail2Ban does and does not do](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#o-que-faz)
* [Install it and understand the files](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#instalar)
* [jail.local and the SSH jail](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#configurar-jail)
* [Jails for Nginx](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#jails-nginx)
* [The recidive jail for repeat offenders](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#recidive)
* [Parameters you will tune](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#parametros)
* [Check, unban and view the blocks](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#operacao)
* [Fail2Ban in a layered defense](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#camadas)

Quick answer

Install it with `sudo apt install fail2ban`, create `/etc/fail2ban/jail.local` with ignoreip, bantime and incremental bans, tune the SSH jail and validate with `sudo fail2ban-client -t`. On **Ubuntu 24.04** the default is to read the journal, so jails that read files, such as the Nginx ones and recidive, need `backend = auto`.

## What Fail2Ban does and does not do[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#o-que-faz)

Every server with a public IP gets automated login attempts within minutes of coming online. Fail2Ban watches the system logs, counts the failures from each IP inside a time window and, when the limit is hit, creates a blocking rule in the firewall for a set period. Each set of monitored service, filter, limit and action is called a jail.

What it does not do: it does not stop distributed attacks where thousands of IPs try one password each, it does not replace [key-based login](https://streethosting.com.br/en/guides/vps/passwordless-ssh-login-vps) and it is no use against DDoS, because it only acts after the attempts have already arrived and been logged. It reduces noise and risk; it is not a wall.

## Install it and understand the files[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#instalar)

Update the system before installing. The Ubuntu 24.04 package once shipped a version that would not start with Python 3.12, fixed by an update.

`sudo apt update && sudo apt upgrade sudo apt install fail2ban sudo systemctl enable --now fail2ban sudo fail2ban-client status`

Fail2Ban reads its configuration in layers, and the last value read wins: first `jail.conf`, then the .conf files in `jail.d/`, then `jail.local` and finally the .local files in jail.d. jail.conf holds the defaults and the ready-made jails, switched off; never edit it, because package updates overwrite it. On Ubuntu, the package also installs this file:

`# /etc/fail2ban/jail.d/defaults-debian.conf (Ubuntu 24.04) [DEFAULT] banaction = nftables banaction_allports = nftables[type=allports] backend = systemd [sshd] enabled = true`

Three practical consequences. The SSH jail comes switched on. Bans are applied straight in nftables, in a table of their own, and do not show up in `ufw status`. And the systemd backend, set in DEFAULT, applies to every jail that does not declare its own, which is the case for the Nginx jails and recidive. It reads the journal, which is great for SSH but useless for services that write to a file.

## jail.local and the SSH jail[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#configurar-jail)

All of your changes go into a single file, created from scratch:

`# /etc/fail2ban/jail.local [DEFAULT] ignoreip = 127.0.0.1/8 ::1 203.0.113.10 bantime = 1h findtime = 10m maxretry = 5 bantime.increment = true bantime.maxtime = 1w [sshd] enabled = true mode = aggressive maxretry = 3 # port = 2222`

* **ignoreip:** replace 203.0.113.10 with your static IP, if you have one. If your IP changes, leave only the local addresses and rely on key-based login.
* **bantime.increment:** each new ban of the same IP doubles in length, up to the bantime.maxtime cap. Persistent bots vanish for days; a one-off mistake costs only an hour.
* **mode = aggressive:** the SSH filter has the modes normal, ddos, extra and aggressive. The last one combines them all and also catches connections that give up before authenticating, common in scans.
* **port:** if SSH uses a custom port, set it here. The ban rule blocks only the configured port, and a ban on 22 stops nothing if SSH listens on 2222.

Validate before applying, because a syntax error keeps the service from starting:

`sudo fail2ban-client -t sudo systemctl restart fail2ban sudo fail2ban-client status sshd`

## Jails for Nginx[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#jails-nginx)

Fail2Ban already ships filters for Nginx. The three most useful ones read the error log and block ports 80 and 443. Add them to the same jail.local:

`[nginx-http-auth] enabled = true backend = auto logpath = /var/log/nginx/error.log [nginx-limit-req] enabled = true backend = auto logpath = /var/log/nginx/error.log findtime = 1m maxretry = 10 [nginx-botsearch] enabled = true backend = auto logpath = /var/log/nginx/error.log`

* `nginx-http-auth`: bans whoever gets the username or password wrong on areas protected by Nginx basic authentication.
* `nginx-limit-req`: bans whoever keeps blowing past the rate limit. It only works if you configured limit\_req in Nginx, as the guide on [protecting a web application](https://streethosting.com.br/en/guides/infrastructure/protect-web-application-from-attacks) shows.
* `nginx-botsearch`: bans bots that probe for typical admin panel and installer paths that do not exist on your site.

Before enabling, test whether the filter recognizes the lines in your log. The result shows how many lines matched:

`sudo fail2ban-regex /var/log/nginx/error.log /etc/fail2ban/filter.d/nginx-limit-req.conf`

If the site sits behind a CDN, the log records the CDN's IP, and Fail2Ban would ban the CDN itself, taking the site down for a lot of people. Configure the real IP in Nginx first. And remember that, even with the right IP, a ban in the VPS firewall does not stop anyone coming in through the CDN, because the connection comes from the CDN.

### Other services and custom filters

The `/etc/fail2ban/filter.d/` folder has ready-made filters for dozens of services, such as Postfix, Dovecot, MySQL and FTP servers; jail.conf ships the matching jails, switched off. For your own application, all it takes is for it to log each failed login with the IP on a predictable line. The filter is a regular expression where `<HOST>` marks where the IP is:

`# /etc/fail2ban/filter.d/minha-app.conf [Definition] failregex = ^.*login falhou .* ip=<HOST>$ # no jail.local [minha-app] enabled = true backend = auto logpath = /var/log/minha-app/app.log port = http,https maxretry = 5`

If the application runs as a systemd service and writes only to the journal, keep the systemd backend and replace logpath with `journalmatch = _SYSTEMD_UNIT=minha-app.service`. Either way, test with `fail2ban-regex` before turning it on.

## The recidive jail for repeat offenders[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#recidive)

Recidive is a jail that reads Fail2Ban's own log. When an IP gets banned several times, by any jail, it applies a long ban on all ports. The defaults already come in jail.conf: log at `/var/log/fail2ban.log`, a one-week ban, a one-day window and an action that blocks all ports. All that is left is to switch it on and fix the backend:

`[recidive] enabled = true backend = auto logpath = /var/log/fail2ban.log`

With incremental bans on, recidive is partly redundant for SSH, but it is still useful for crossing jails: an IP that was banned on Nginx and then tries SSH is the same bot, and deserves to be taken out of circulation everywhere.

## Parameters you will tune[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#parametros)

| Parameter         | What it controls                   | Default                    | Suggestion                                  |
| ----------------- | ---------------------------------- | -------------------------- | ------------------------------------------- |
| maxretry          | Failures before the ban            | 5                          | 3 on SSH, 10 on the request limit           |
| findtime          | Window for counting failures       | 10 minutes                 | 10 minutes; 1 minute on the request limit   |
| bantime           | Ban duration                       | 10 minutes                 | 1 hour, with incremental bans               |
| bantime.increment | Ban grows with each repeat offense | Off                        | On, capped at one week                      |
| ignoreip          | Addresses never banned             | Only the machine's own IPs | Add your static IP, if you have one         |
| backend           | Where events come from             | systemd on Ubuntu 24.04    | auto on jails that read files               |
| banaction         | How the ban is applied             | nftables on Ubuntu 24.04   | Keep it; ufw if you want to see bans in UFW |
| mode (sshd)       | Which SSH messages count           | normal                     | aggressive                                  |

## Check, unban and view the blocks[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#operacao)

The day-to-day commands:

`# active jails and a summary of one jail sudo fail2ban-client status sudo fail2ban-client status sshd # unban in one jail or in all of them sudo fail2ban-client set sshd unbanip 198.51.100.23 sudo fail2ban-client unban 198.51.100.23 # ban by hand, useful for testing the action sudo fail2ban-client set sshd banip 198.51.100.23 # view the blocks in the firewall and follow the log sudo nft list table inet f2b-table sudo tail -f /var/log/fail2ban.log`

A jail's status shows how many failures are being counted, the total bans and the list of IPs banned right now. On jails that read files, it also shows the list of monitored files; if that list is empty, the backend or the logpath is wrong. In `/var/log/fail2ban.log`, each counted failure appears as a Found line and each block as a NOTICE line with the jail name, the word Ban and the IP. A spike of Found lines from many different IPs, each with one or two attempts, is a sign of a distributed attack, which Fail2Ban cannot stop on its own.

Prefer to see the bans alongside your [UFW](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) rules? Put `banaction = ufw` in the DEFAULT section of jail.local. Each ban becomes a rule at the top of UFW. Plain nftables is more efficient with many bans, but both work. If you ban yourself by mistake, the VPS console in the panel is still reachable.

## Fail2Ban in a layered defense[](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#camadas)

* Key-based login on and password login off in SSH
* Direct root login disabled
* Firewall opening only the ports you need
* SSH jail on the real port, with incremental bans
* Nginx jails with backend auto and a tested filter
* Recidive on for repeat offenders

Fail2Ban is the layer that reacts. The layers that prevent are the SSH configuration itself, covered in the guide on [secure SSH on a VPS](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps), and the exposure strategy, with IP restriction or a VPN, in [protecting SSH against brute force](https://streethosting.com.br/en/guides/infrastructure/protect-ssh-from-brute-force).

On the [StreetHosting VPS](https://streethosting.com.br/en/vps), with KVM and root access, Fail2Ban and nftables work without restrictions, and the Anti-DDoS included in the network handles the volume that no jail could. Fail2Ban is light and runs fine from the Xeon VPS at R$ 23.00 or the Ryzen 9 9950X at R$ 40.00. For large projects with many exposed services, the [dedicated servers](https://streethosting.com.br/en/dedicated) in São Paulo come with 10 Gbps, Anti-DDoS and full root access, starting at R$ 1,499.00, delivered within 6 days.

In this guide

* [What Fail2Ban does and does not do](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#o-que-faz)
* [Install it and understand the files](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#instalar)
* [jail.local and the SSH jail](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#configurar-jail)
* [Jails for Nginx](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#jails-nginx)
* [The recidive jail for repeat offenders](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#recidive)
* [Parameters you will tune](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#parametros)
* [Check, unban and view the blocks](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#operacao)
* [Fail2Ban in a layered defense](https://streethosting.com.br/en/guides/vps/fail2ban-ssh-vps-setup#camadas)

## Frequently asked questions

Does Fail2Ban replace the SSH key?

No. The key eliminates password guessing, and Fail2Ban cuts the noise by banning whoever keeps trying. With password login disabled in SSH, a brute-force attack has no chance of success; Fail2Ban is still useful to clean up the logs and save resources.

Why does the Nginx jail not ban anyone on Ubuntu 24.04?

Almost always it is the backend. The Ubuntu 24.04 package sets the systemd backend as the default, the Nginx jails inherit that value, and Nginx writes to a file, not to the journal. Add backend = auto to the jail and check in its status whether the log file shows up in the monitored list.

I banned my own IP. How do I undo it?

Connect from another network, such as your phone's 4G, or through the VPS console in the client area, and run the Fail2Ban client unban command with your IP. Afterward, if your IP is static, add it to ignoreip so it does not happen again.

How long should I ban an IP?

One hour is a good start for SSH. With incremental bans on, each repeat offense doubles the time up to a cap, and the recidive jail takes anyone banned several times in the same day out of circulation for a week. A permanent ban rarely pays off, because IPs change hands.

Does Fail2Ban work with the site behind a CDN?

Only with adjustments. Nginx has to log the visitor's real IP, and even then banning that IP in the VPS firewall does nothing, because the connection arrives through the CDN. In that setup the block has to happen at the CDN itself or in Nginx, and Fail2Ban is left for SSH and services reached directly.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen) [See dedicated servers Exclusive hardware in São Paulo with NVMe and Anti-DDoS.](https://streethosting.com.br/en/dedicated)

## Related guides

[VPS Intermediate How to secure SSH on a Linux VPS: keys, passwords, fail2ban SSH is usually the first target on any VPS with a public IP. This guide walks through a practical routine that cuts the risk without complicating your day: an ED25519 key, password-free login, admin access through sudo, blocking of automated attempts and a periodic review of authorized keys. 4 min Read guide](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps) [VPS Beginner UFW on Ubuntu VPS: firewall rules without losing SSH UFW makes the Ubuntu firewall simpler, but one rule in the wrong order locks you out of your VPS. Learn how to enable it without losing SSH, open only what you need, deal with Docker, and get back in through the console if something goes wrong. 10 min Read guide](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) [VPS Intermediate How to set up passwordless SSH key login on a VPS Key-based login is safer and easier than a password. You generate a key pair, copy the public key to the server, and log in without typing anything. Here is how, in a few steps. 3 min Read guide](https://streethosting.com.br/en/guides/vps/passwordless-ssh-login-vps)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
