Ubuntu 14.04服务器Fail2Ban v0.8.11未封禁重复SSH失败登录IP问题排查
Alright, let's walk through troubleshooting your Fail2Ban issue step by step—since you're using the default Ubuntu/Debian repo config and only seeing startup logs in /var/log/fail2ban.log, here's what to check:
1. Confirm the SSH Jail is Enabled
First, double-check that the SSH jail is actually turned on (default should be, but it's worth verifying). Run this command to inspect the default SSH jail config:
cat /etc/fail2ban/jail.conf | grep -A 10 "\[ssh\]"
Look for the line enabled = true. If it's set to false, edit /etc/fail2ban/jail.conf (or create a /etc/fail2ban/jail.local override to avoid overwriting defaults) to set it to true, then restart the service:
service fail2ban restart
2. Verify the SSH Log Path is Correct
Fail2Ban relies on monitoring the right log file for failed SSH attempts. On Ubuntu 14.04, SSH logs are typically stored at /var/log/auth.log. Check if your jail config points here:
cat /etc/fail2ban/jail.conf | grep -A 5 "\[ssh\]" | grep logpath
If the path is incorrect, update it in your jail config and restart Fail2Ban. Also, ensure the Fail2Ban user has permission to read this log:
ls -l /var/log/auth.log groups fail2ban
The log should be owned by root:adm—if the fail2ban user isn't in the adm group, add it with:
usermod -aG adm fail2ban service fail2ban restart
3. Test the SSH Filter Rules
Fail2Ban uses regex filters to detect failed login attempts. Let's verify the default sshd filter matches your auth log entries:
fail2ban-regex /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf
Look at the "Matches" section of the output. If it shows zero matches for your failed SSH attempts, the filter regex might not align with your SSH daemon's log format. For Ubuntu 14.04, a typical failed login line looks like:
Jun 10 12:34:56 your-server sshd[1234]: Failed password for root from 192.168.1.100 port 12345 ssh2
If the filter isn't catching this, you may need to tweak the regex in /etc/fail2ban/filter.d/sshd.conf, but the default should work for standard OpenSSH on Ubuntu 14.04.
4. Check if Fail2Ban is Monitoring the SSH Jail
Use the Fail2Ban client to check the status of the SSH jail:
fail2ban-client status ssh
You should see output listing "Currently banned" IPs, "Total banned" count, and confirm the jail is active. If you get an error like "Jail 'ssh' does not exist", go back to step 1 to ensure the jail is enabled.
5. Manually Trigger a Ban Test
Intentionally trigger several failed SSH login attempts (the default maxretry is 5, so try 6+ times). Then:
- Check
/var/log/auth.logto confirm the failed attempts are being logged. - Re-run
fail2ban-client status sshto see if your test IP is now banned. - Check iptables to see if the IP is blocked:
iptables -L -n
Look for a fail2ban-SSH chain with a rule dropping traffic from your test IP.
6. Increase Log Verbosity for Debugging
If you're still not seeing any action in fail2ban.log, bump the log level to DEBUG to get more details. Edit /etc/fail2ban/fail2ban.conf and set:
loglevel = DEBUG
Restart Fail2Ban, trigger more failed logins, then check /var/log/fail2ban.log—you should see detailed logs about whether Fail2Ban is detecting failed attempts, trying to apply bans, or hitting errors. Remember to set loglevel back to INFO once you're done debugging to avoid bloating logs.
7. Verify Fail2Ban Runs with Proper Permissions
Fail2Ban needs root privileges to modify iptables rules. Confirm it's running as root:
ps aux | grep fail2ban
If the process is running under a non-root user, check the startup script at /etc/init.d/fail2ban to ensure it's configured to run as root.
内容的提问来源于stack exchange,提问作者Sean Hammond

