{"id":13628,"date":"2026-03-11T10:54:09","date_gmt":"2026-03-11T05:24:09","guid":{"rendered":"https:\/\/www.youstable.com\/blog\/?p=13628"},"modified":"2026-09-07T11:08:34","modified_gmt":"2026-09-07T05:38:34","slug":"fix-fail2ban-on-linux","status":"publish","type":"post","link":"https:\/\/www.youstable.com\/blog\/fix-fail2ban-on-linux\/","title":{"rendered":"How to Fix Fail2ban on Linux Server &amp; Restore SSH Protection"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>To fix Fail2ban on a Linux server<\/strong>, confirm the service and jails are running, inspect \/var\/log\/fail2ban.log for errors, verify each jail\u2019s logpath and backend (journald or file) per distro, test filters with fail2ban regex, ensure firewall actions match iptables\/nftables\/UFW\/firewalld, then reload or restart Fail2ban and re-test bans.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re troubleshooting how to fix Fail2ban on Linux server environments, this guide walks you through quick diagnostics and precise fixes. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You\u2019ll learn how Fail2ban detects attacks, why jails fail to ban, and the exact steps to repair filters, logpaths, and firewall actions so your server blocks brute force attempts again.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-fail2ban-works-quick-primer\">How Fail2ban Works (Quick Primer)<\/h2>\n\n\n\n<div class=\"wp-block-media-text has-media-on-the-right is-stacked-on-mobile\"><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.youstable.com\/blog\/what-is-fail2ban-on-linux-server\">Fail2ban protects Linux servers<\/a> by reading logs (files or journald), matching malicious patterns via filters, and applying actions (e.g., firewall rules) to ban IPs. Its core pieces:<\/p>\n<\/div><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1168\" height=\"784\" src=\"https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/How-Fail2ban-Works-Quick-Primer.png\" alt=\"How Fail2ban Works (Quick Primer)\" class=\"wp-image-14140 size-full\" srcset=\"https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/How-Fail2ban-Works-Quick-Primer.png 1168w, https:\/\/www.youstable.com\/blog\/wp-content\/uploads\/2025\/12\/How-Fail2ban-Works-Quick-Primer-150x101.png 150w\" sizes=\"auto, (max-width: 1168px) 100vw, 1168px\" \/><\/figure><\/div>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Jails:<\/strong> Enable protection for a service (e.g., sshd).<\/li>\n\n\n\n<li><strong>Filters:<\/strong> Regex rules that detect suspicious log entries.<\/li>\n\n\n\n<li><strong>Actions: <\/strong>What happens on a match (ban\/unban via firewall).<\/li>\n\n\n\n<li><strong>Backend: <\/strong>Where logs are read from (file or systemd\/journald).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"search-intent-quick-fix-checklist\">Search Intent: Quick Fix Checklist<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When Fail2ban isn\u2019t banning, the culprit is usually one of these:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Fail2ban service\/jails not running or misconfigured.<\/li>\n\n\n\n<li>Wrong logpath or backend (journald vs file logs).<\/li>\n\n\n\n<li>Filter regex doesn\u2019t match your logs.<\/li>\n\n\n\n<li>Firewall action incompatible with iptables\/nftables\/UFW\/firewalld.<\/li>\n\n\n\n<li><strong>Parameters too strict\/loose:<\/strong> bantime, findtime, maxretry, ignoreip.<\/li>\n\n\n\n<li>Conflicts with cloud firewalls or custom network policies.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-to-fix-fail2ban-on-linux-server-step-by-step\">How to Fix Fail2ban on Linux Server (Step by Step)<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"1-verify-the-service-and-jail-status\">1) Verify the service and jail status<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">First, ensure <a href=\"https:\/\/www.youstable.com\/blog\/install-fail2ban-on-linux\/\">Fail2ban is installed<\/a>, enabled, and the jails you expect are active.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Service health\nsudo systemctl status fail2ban\nsudo systemctl enable fail2ban\n\n# See what Fail2ban thinks is running\nsudo fail2ban-client ping\nsudo fail2ban-client status\nsudo fail2ban-client status sshd   # replace sshd with your jail name<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If the jail you need isn\u2019t listed, it isn\u2019t enabled. You enable jails in jail.local (not jail.conf).<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"2-read-fail2ban-logs-and-enable-debug-temporarily\">2) Read Fail2ban logs and enable debug temporarily<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Fail2ban tells you why it didn\u2019t ban in its own log. Look for errors like \u201cUnable to read log file,\u201d \u201cNo failure-ID found,\u201d or \u201caction start command returned error.\u201d<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Primary log\nsudo tail -n 200 \/var\/log\/fail2ban.log\n\n# Temporarily increase verbosity (revert after fix)\nsudo sed -i 's\/^loglevel.*\/loglevel = DEBUG\/' \/etc\/fail2ban\/fail2ban.conf\nsudo systemctl restart fail2ban\nsudo tail -f \/var\/log\/fail2ban.log<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Once fixed, set loglevel back to INFO and restart to avoid noisy logs.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"3-fix-logpath-and-backend-mismatches\">3) Fix logpath and backend mismatches<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Most banning failures come from wrong log sources. Linux distributions differ:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Debian\/Ubuntu<\/strong>: SSH logs in <code>\/var\/log\/auth.log<\/code> by default.<\/li>\n\n\n\n<li><strong>RHEL\/CentOS\/AlmaLinux\/Rocky:<\/strong> SSH logs in <code>\/var\/log\/secure<\/code>.<\/li>\n\n\n\n<li>Pure journald setups: Use <code>backend = systemd<\/code> (no logpath needed for some jails).<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code># Example: choose one depending on your system\n&#91;DEFAULT]\n# If you use classic log files\nbackend = auto\n\n# OR for journald systems\n# backend = systemd<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Check your jail\u2019s <code>logpath<\/code> matches your OS. If rsyslog is disabled and logs only go to journald, set <code>backend = systemd<\/code> in [DEFAULT] or that specific jail.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"4-validate-filters-with-fail2ban-regex\">4) Validate filters with fail2ban-regex<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Filters may not match local log formats, especially after version upgrades or custom log formats. Test the filter against your logs.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># For file-based logs\nsudo fail2ban-regex \/var\/log\/auth.log \/etc\/fail2ban\/filter.d\/sshd.conf\n\n# For RHEL-like\nsudo fail2ban-regex \/var\/log\/secure \/etc\/fail2ban\/filter.d\/sshd.conf\n\n# Print matches to confirm\nsudo fail2ban-regex --print-all-matched \/var\/log\/auth.log \/etc\/fail2ban\/filter.d\/sshd.conf<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If there are zero matches despite obvious failures in the log, your filter or logpath is wrong. Update the filter (or pick the correct one) and retest.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"5-make-firewall-actions-compatible-iptables-nftables-ufw-firewalld\">5) Make firewall actions compatible (iptables, nftables, UFW, firewalld)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Fail2ban must use an action that matches your firewall stack. Wrong actions lead to \u201cban succeeded = no\u201d or restore errors.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.youstable.com\/blog\/fix-iptables-on-linux-server\"><strong>iptables<\/a> (legacy):<\/strong> <code>action = iptables-multiport<\/code><\/li>\n\n\n\n<li><strong>nftables:<\/strong> <code>action = nftables-multiport<\/code> (Fail2ban 0.11+)<\/li>\n\n\n\n<li><strong>UFW:<\/strong> <code>action = ufw<\/code><\/li>\n\n\n\n<li><strong>firewalld: <\/strong><code>action = firewallcmd-rich-rules<\/code><\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code># Example per-jail override\n&#91;sshd]\nenabled = true\nport    = ssh\nfilter  = sshd\nbackend = auto\nlogpath = \/var\/log\/auth.log\nmaxretry = 5\nfindtime = 10m\nbantime  = 1h\n\n# Pick the action that matches your firewall\n# action = iptables-multiport\n# action = nftables-multiport\n# action = ufw\n# action = firewallcmd-rich-rules<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Also confirm no cloud firewall (e.g., AWS Security Groups) or upstream WAF conflicts with local bans. Cloud firewalls don\u2019t block outbound, so local bans still matter.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"6-use-jail-local-not-jail-conf-and-restart-correctly\">6) Use jail.local, not jail.conf (and restart correctly)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Never edit <code>\/etc\/fail2ban\/jail.conf<\/code>; it\u2019s overwritten by updates. Put your changes in <code>\/etc\/fail2ban\/jail.local<\/code> or <code>\/etc\/fail2ban\/jail.d\/*.conf<\/code>. After changes, reload or restart the service.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># Safer reload (keeps bans)\nsudo fail2ban-client reload\n\n# Full restart (drops state)\nsudo systemctl restart fail2ban<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"7-working-ssh-jail-examples-ubuntu-debian-and-rhel-family\">7) Working SSH jail examples (Ubuntu\/Debian and RHEL family)<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code># \/etc\/fail2ban\/jail.local\n&#91;DEFAULT]\nignoreip = 127.0.0.1\/8 ::1\nbantime  = 1h\nfindtime = 10m\nmaxretry = 5\nbackend  = auto\n# For pure journald setups you can use:\n# backend = systemd\n\n&#91;sshd]\nenabled = true\nport    = ssh\nfilter  = sshd\n\n# Ubuntu\/Debian\nlogpath = \/var\/log\/auth.log\n\n# RHEL\/CentOS\/AlmaLinux\/Rocky (use this instead)\n# logpath = \/var\/log\/secure\n\n# Choose an action compatible with your firewall\n# action = nftables-multiport\n# action = iptables-multiport\n# action = ufw\n# action = firewallcmd-rich-rules<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>After saving, reload and verify:<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo fail2ban-client reload\nsudo fail2ban-client status sshd\nsudo tail -f \/var\/log\/fail2ban.log<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"8-tune-ban-logic-bantime-findtime-maxretry-ignoreip-recidive\">8) Tune ban logic: bantime, findtime, maxretry, ignoreip, recidive<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Too loose settings miss offenders; too-strict settings may ban legitimate users.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>bantime:<\/strong> How long an IP stays banned (e.g., 1h, 24h, -1 for permanent).<\/li>\n\n\n\n<li><strong>findtime: <\/strong>Window to count failures (e.g., 10m).<\/li>\n\n\n\n<li><strong>maxretry: <\/strong>Number of failures within findtime before ban (e.g., 5).<\/li>\n\n\n\n<li><strong>ignoreip: <\/strong>CIDRs never banned (your office\/VPN; avoid 0.0.0.0\/0 by mistake).<\/li>\n\n\n\n<li><strong>recidive:<\/strong> A jail that bans repeat offenders longer. Enable by including the provided recidive jail and using a long bantime.<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code># Example: enable recidive for chronic attackers\n&#91;recidive]\nenabled  = true\nfilter   = recidive\nlogpath  = \/var\/log\/fail2ban.log\nbantime  = 7d\nfindtime = 1d\nmaxretry = 5\n# action must match your firewall stack<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"9-selinux-apparmor-and-permissions\">9) SELinux\/AppArmor and permissions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Fail2ban runs as root and typically can read logs. If you see permission errors, validate log file permissions and SELinux denials. On SELinux systems, check <code>\/var\/log\/audit\/audit.log<\/code> for AVCs. Adjust rsyslog\/journal permissions or temporarily set permissive mode just for testing (not recommended in production).<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># <a href=\"https:\/\/www.youstable.com\/blog\/install-selinux-on-linux\/\">Check SELinux<\/a> denials\nsudo ausearch -m avc -ts recent\n\n# Temporarily permissive (testing only)\n# sudo setenforce 0\n# sudo setenforce 1  # turn back enforcing<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"10-reload-restart-and-enable-on-boot\">10) Reload, restart, and enable on boot<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When you\u2019ve fixed configuration, reload to apply changes without dropping existing bans. Enable the service on boot.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo fail2ban-client reload\nsudo systemctl restart fail2ban   # if needed\nsudo systemctl enable fail2ban\nsudo fail2ban-client status<\/code><\/pre>\n\n\n\n<p class=\"has-ast-global-color-1-background-color has-background wp-block-paragraph\"><strong>Also Read: <a href=\"https:\/\/www.youstable.com\/blog\/fix-docker-on-linux\">Fix Docker on Linux Server &#8211; Docker Recovery Guide<\/a><\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"common-errors-and-fast-fixes\">Common Errors and Fast Fixes<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u201cNo such file or directory\u201d for logp<\/strong>ath: Correct the <code>logpath<\/code> to your OS\u2019s log file or switch to <code>backend = systemd<\/code>.<\/li>\n\n\n\n<li><strong>iptables restore or nft errors:<\/strong> Switch to the appropriate action (<code>iptables-multiport<\/code> vs <code>nftables-multiport<\/code>) or install the firewall package.<\/li>\n\n\n\n<li><strong>Jail not found: <\/strong>The jail isn\u2019t enabled in <code>jail.local<\/code> or the file in <code>jail.d<\/code> has syntax errors.<\/li>\n\n\n\n<li><strong>No matches in fail2ban regex:<\/strong> Your filter doesn\u2019t match the log format; update the filter or point to the correct log.<\/li>\n\n\n\n<li><strong>Ban appears but traffic still passes: <\/strong>Another firewall chain, cloud firewall, or network path overrides local rules; inspect full firewall policy and routing.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"10-step-recovery-playbook-copy-paste\">10 Step Recovery Playbook (Copy\/Paste)<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>systemctl status fail2ban<\/li>\n\n\n\n<li>fail2ban client status; status sshd<\/li>\n\n\n\n<li>tail -n 200 \/var\/log\/fail2ban.log<\/li>\n\n\n\n<li>Set loglevel = DEBUG, restart, re-check logs<\/li>\n\n\n\n<li>Verify logpath (auth.log vs secure) or set backend = systemd<\/li>\n\n\n\n<li>fail2ban regex logpath filter.d\/sshd.conf<\/li>\n\n\n\n<li>Pick the correct action (iptables, nftables, ufw, firewalld)<\/li>\n\n\n\n<li>Move edits to jail.local; reload Fail2ban<\/li>\n\n\n\n<li>Tune bantime\/findtime\/maxretry; set ignoreip<\/li>\n\n\n\n<li>Enable on boot; re-test with controlled failed logins<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"best-practices-to-keep-fail2ban-effective\">Best Practices to Keep Fail2ban Effective<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use key based SSH auth and change the SSH port only as a supplemental measure.<\/li>\n\n\n\n<li>Enable recidive and longer bans for repeat offenders.<\/li>\n\n\n\n<li>Keep filters updated; new daemon versions change log formats.<\/li>\n\n\n\n<li>Monitor Fail2ban with system logs or external alerts.<\/li>\n\n\n\n<li>Pair Fail2ban with a hardened firewall baseline and minimal attack surface.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"professional-help-when-to-call-the-experts\">Professional Help: When to Call the Experts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you still can\u2019t get Fail2ban to ban reliably, you may have deeper firewall conflicts, custom logging, or distributed entry points. <strong><a href=\"https:\/\/www.youstable.com\/\">YouStable\u2019s managed VPS &amp; dedicated servers<\/a><\/strong> include hands on security hardening, firewall tuning, and Fail2ban configuration. Our engineers can audit your stack and implement a resilient, monitored banning strategy without downtime.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"useful-commands-reference\">Useful Commands Reference<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code># Check jail status and bans\nsudo fail2ban-client status\nsudo fail2ban-client status sshd\n\n# Unban\/ban an IP\nsudo fail2ban-client set sshd unbanip 1.2.3.4\nsudo fail2ban-client set sshd banip 1.2.3.4\n\n# Test a filter against a log\nsudo fail2ban-regex \/var\/log\/auth.log \/etc\/fail2ban\/filter.d\/sshd.conf\n\n# Switch action (example)\n# In \/etc\/fail2ban\/jail.local:\n# action = nftables-multiport\n\n# Restart\/reload\nsudo fail2ban-client reload\nsudo systemctl restart fail2ban<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"faqs\">FAQs<\/h2>\n\n\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-question-1765864144588\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"why-is-fail2ban-not-banning-ssh-attackers\">Why is Fail2ban not banning SSH attackers?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Typically because the SSH jail isn\u2019t enabled, the logpath is wrong (auth.log vs secure), the filter doesn\u2019t match the log format, or the firewall action is incompatible. Run u003ccodeu003efail2ban-client status sshdu003c\/codeu003e, test with u003ccodeu003efail2ban-regexu003c\/codeu003e, and ensure the action matches your firewall (iptables, nftables, UFW, or firewalld).<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765864162090\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"whats-the-difference-between-bantime-and-findtime\">What\u2019s the difference between bantime and findtime?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>bantime is how long an IP remains blocked after triggering a ban. findtime is the time window during which maxretry failures are counted. For example, with findtime=10m and maxretry=5, five failures within 10 minutes lead to a ban lasting bantime (e.g., 1h or 24h).<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765864177419\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"how-do-i-unban-or-reban-an-ip-in-fail2ban\">How do I unban or reban an IP in Fail2ban?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Use the jail-specific commands: u003ccodeu003esudo fail2ban-client set u0026lt;jailu003e unbanip 1.2.3.4u003c\/codeu003e to unban and u003ccodeu003esudo fail2ban-client set u0026lt;jailu003e banip 1.2.3.4u003c\/codeu003e to force a ban. Confirm with u003ccodeu003efail2ban-client status u0026lt;jailu003eu003c\/codeu003e and your firewall rules.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765864187765\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"does-fail2ban-work-with-cloudflare-or-a-cloud-load-balancer\">Does Fail2ban work with Cloudflare or a cloud load balancer?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, but ensure Fail2ban sees the real client IPs. If your service sits behind Cloudflare or an LB, configure real IP headers and logs (e.g., u003ccodeu003ereal_ipu003c\/codeu003e for Nginx) so filters match clients, not the proxy IP. Consider banning at the app layer or via provider firewall APIs where appropriate.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-question-1765864200694\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \" class=\"rank-math-question \" id=\"should-i-use-backendsystemd-or-file-based-logs\">Should I use backend=systemd or file based logs?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Use file based logs if you have rsyslog writing to files like u003ccodeu003e\/var\/log\/auth.logu003c\/codeu003e or u003ccodeu003e\/var\/log\/secureu003c\/codeu003e. Use u003ccodeu003ebackend = systemdu003c\/codeu003e when logs are only in journald. Pick one that matches your environment; mixing causes missed matches and failed bans.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>To fix Fail2ban on a Linux server, confirm the service and jails are running, inspect \/var\/log\/fail2ban.log for errors, verify each [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":19069,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"iawp_total_views":273,"footnotes":""},"categories":[350,2262],"tags":[],"class_list":["post-13628","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-knowledgebase","category-kb-security"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/comments?post=13628"}],"version-history":[{"count":1,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13628\/revisions"}],"predecessor-version":[{"id":23063,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/13628\/revisions\/23063"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media\/19069"}],"wp:attachment":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media?parent=13628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/categories?post=13628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/tags?post=13628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}