Fail2ban SSH Hardening on Ubuntu Servers
Reduce brute-force noise with Fail2ban jails, whitelist IPs, and sensible ban durations.
Threat background
Internet-facing SSH endpoints see constant password guessing even when password auth is disabled. Fail2ban watches auth logs and temporarily blocks offending IPs with firewall rules.
Vcom Web Tech pairs Fail2ban with key-only SSH and non-default ports only when clients request obscurity, knowing security through obscurity is not sufficient alone.
Whitelist office and CI IPs to avoid locking out deploy pipelines.
Jail configuration
Enable sshd jail with findtime and maxretry tuned to your tolerance for mistakes. Ban times of one hour deter scanners without permanent lockout.
Use recidive jail for repeat offenders when appropriate.
Test jails with intentional failed logins from a disposable IP.
Nginx jails
Extend Fail2ban to Nginx logs for repeated 404 probes or login form abuse when applications expose such paths.
Custom filters require regex maintenance when log formats change.
Coordinate with CDN IPs so you do not ban edge nodes shared by many users.
Operations
Monitor ban actions in Fail2ban logs. Sudden spikes may indicate coordinated attacks or misconfigured clients.
Document unban procedures for on-call when legitimate users trigger rules.
Review Fail2ban after SSH or Nginx package upgrades change log paths.
Additional operational notes
Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.
When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.
Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.
Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.
Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.
Additional operational notes
Operational excellence on Linux hosting requires documenting every change to Nginx, systemd, PM2, Docker, and DNS in a runbook your team shares. Vcom Web Tech clients benefit when staging environments mirror production firewall rules, TLS versions, and mail authentication so surprises appear before customers notice. Schedule quarterly reviews of backups, certificate expiry, DMARC reports, and monitoring alerts even when traffic feels stable.
When incidents occur, capture timelines and root causes in blameless postmortems. Patterns from past 502 errors, failed renewals, or bounce spikes inform checklists for the next deployment. Training new team members on SSH access, log locations, and escalation paths reduces dependency on single maintainers.
Security patches, dependency upgrades, and framework migrations should ride the same CI pipelines that deploy application code. Automate smoke tests that hit health endpoints and send test mail through staging SMTP relays. Small consistent investments beat heroic firefighting during launch weekends.
Capacity planning matters on VPS hosts where vertical scaling has limits. Watch disk inode usage, connection counts, and database connection pools as traffic grows. Proactive upgrades cost less than emergency migrations during peak sales or campaign sends.
Finally, communicate with stakeholders using plain language about risk, downtime windows, and deliverability metrics. Technical depth supports trust when email authentication or deployment strategy changes affect revenue-facing systems.