Alternatives to Fail2ban?

Alternatives to Fail2ban?

4 pointsby jech4 comments

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • there is fail2zig seems to be exactly what you looking for

    https://fail2zig.com

  • Disable password authentication and ignore the noise.
  • Do you really need SSH exposed?

    If not, use something like WireGuard (or Tailscale) and bind only to that interface.

    You can also change the default port, your logs will quiet down dramatically.

    Lastly, if you have a long enough passphrase with enough entropy/randomness, password authentication being enabled is probably fine, you can also set only a specific user allowed to SSH for additional hardening.

  • This isn't for everyone and it will block old ssh libraries (libssh, go ssh, etc...), windows and others but if you only have OpenSSH 10+ and that's all you connect with then this method [1] has worked well for me. It gets botters to exclude my nodes that expose SSH on purpose (such as public anonymous SFTP). If trying it out test from an out of band console first.

    Edit: I should add, there will still be some syslog entries, but that can be filtered out using regex filters in rsyslog one so desired. Only do so once it is confirmed most of the brute forcing has stopped.

    [1] - https://nochan.net/b/Internet-Crap/20260108-Confuse-Some-SSH...

  • > an ssh server exposed to the Internet. I... still allow password authentication in case of trouble

    You gotta get over that eventually and really, the sooner the better.

  • sshguard is exactly this - single C binary, no interpreter needed. It tails your logs (journalctl/syslog) and bans offenders via iptables/nftables/pf. No Python, no dependencies beyond the firewall backend: https://www.sshguard.net/

Explore Birbla archives