SysAdmin Tools

Fail2ban Jail Generator

Create a custom jail.local configuration for SSH, Apache, Nginx, mail and more — tune ban policy and copy it straight to your server.


Advertisement

Important — Use at Your Own Risk

This tool generates configuration for reference and learning purposes only.

Before applying any generated config to a production server:

  • Test in a staging/development environment first
  • Understand each option before applying
  • Take a full backup of existing configuration
  • Verify compatibility with your OS version
  • Wrong security settings can lock you out of your server

SysAdmin Tools is not responsible for server outages, data loss or security issues caused by applying generated configurations.

1. Service to Protect
2. Jail Settings
3. Ban Settings

Failed attempts before ban

Time window to count failures

How long to ban the IP

4. Action Settings

IPs never banned (space separated)

jail.local
[sshd]
enabled  = true
port     = 22
filter   = sshd
logpath  = /var/log/auth.log
maxretry = 5
findtime = 600
bantime  = 3600
action   = %(action_)s
ignoreip = 127.0.0.1/8 ::1

Advertisement

Advertisement

This fail2ban jail generator builds a ready-to-paste jail.local configuration for any service you want to protect from brute-force attacks — SSH, Apache, Nginx, Postfix, Dovecot, WordPress and more. Pick a service, tune the ban settings, and copy the generated jail block straight into /etc/fail2ban/jail.local.

Fail2ban is an intrusion-prevention tool that scans log files for repeated authentication failures and bans the offending IP with iptables (or nftables/firewalld) for a configurable period. The hard part is remembering the exact directive names and sensible values for maxretry, findtime and bantime. This fail2ban config generator fills in the correct filter, port and logpath for each service automatically, so you get a correct fail2ban jail without reading the manual.

Everything runs in your browser — no data is sent anywhere. Use it to create a fail2ban ssh jail configuration, a fail2ban nginx jail config, or a custom jail with your own filter name, then apply it and reload fail2ban.

How to Use the Fail2ban Jail Generator

  1. 1

    Choose the service to protect

    Select SSH, Apache, Nginx, Postfix, Dovecot, WordPress or a custom filter. The port, filter name and log path are auto-filled with sensible defaults for that service.

  2. 2

    Adjust the jail settings

    Confirm the enabled toggle, port, filter and logpath. Override any of them if your server uses non-standard paths or ports.

  3. 3

    Set the ban policy

    Set maxretry (failures allowed), findtime (the window to count them in) and bantime (how long to ban). Use the unit dropdowns for minutes/hours/days, or tick permanent ban for bantime = -1.

  4. 4

    Choose an action and whitelist

    Pick a ban action — plain ban, or ban plus whois/mail/log — and add any IPs to ignoreip so you never lock yourself out.

  5. 5

    Copy and apply

    Click Generate, copy the jail block into /etc/fail2ban/jail.local, then run sudo systemctl restart fail2ban and check it with fail2ban-client status.

Understanding the Generated jail.local

A fail2ban jail ties together four things: a filter (a regex that recognises a failed login in a log), a logpath (the file to watch), a set of thresholds (maxretry, findtime, bantime), and an action (how to ban). Jails live in jail.local, which overrides the package-supplied jail.conf so your settings survive updates. The three numbers are the heart of a jail. maxretry is how many matching failures are allowed before a ban. findtime is the sliding window (in seconds) those failures must occur within. bantime is how long the IP stays banned — a positive number of seconds, or -1 for a permanent ban. For example, maxretry = 5, findtime = 600, bantime = 3600 means "five failures within ten minutes earns a one-hour ban". The action controls what happens on a ban. %(action_)s simply bans the IP; %(action_mw)s also emails a whois report; %(action_mwl)s emails the whois report plus the offending log lines. Always set ignoreip to include your own trusted IPs (and 127.0.0.1/8 ::1) so fail2ban never bans you.
FieldDescription
[jailname]The jail section header, e.g. [sshd]. Names the jail and groups its directives.
enabledtrue activates the jail; false leaves it defined but inactive.
portThe port(s) the ban action blocks, e.g. ssh or 80,443.
filterThe filter (regex ruleset) under /etc/fail2ban/filter.d used to detect failures.
logpathThe log file fail2ban scans for authentication failures.
maxretryNumber of failures within findtime before the IP is banned.
findtimeThe window, in seconds, over which failures are counted.
bantimeHow long a ban lasts in seconds; -1 means a permanent ban.
ignoreipSpace-separated IPs/CIDRs that are never banned — include your own IP.

Advertisement

Common Fail2ban Jail Use Cases

Stop SSH brute-force attacks

Generate an [sshd] jail watching /var/log/auth.log that bans an IP after a handful of failed logins. This is the single most useful fail2ban jail on any internet-facing Linux server.

Protect a web login (WordPress, admin panels)

Create a jail using the Nginx or Apache auth filter, or a custom WordPress filter, to ban IPs hammering wp-login.php or a mod_auth protected area.

Harden mail services

Add Postfix SMTP and Dovecot IMAP jails to ban clients repeatedly failing SMTP AUTH or IMAP login — a common source of credential-stuffing on mail servers.

Permanent bans for persistent offenders

Set bantime to -1 to permanently ban IPs for sensitive services, while keeping a generous ignoreip list so your own addresses are always allowed.

Fail2ban Jail Generator — Frequently Asked Questions

What is fail2ban and how does it work?
Fail2ban is an intrusion-prevention daemon for Linux. It continuously scans log files (such as /var/log/auth.log) for patterns that indicate malicious activity — most commonly repeated authentication failures — and when an IP crosses a threshold, it adds a firewall rule (via iptables, nftables or firewalld) to block that IP for a set time. Each watched service is configured as a "jail" that combines a filter, a log path, and ban thresholds.
What is a fail2ban jail?
A jail is a single unit of protection in fail2ban, written as a section like [sshd] in jail.local. It specifies which log file to monitor (logpath), which filter regex to match failures with (filter), which ports to ban (port), and the ban policy (maxretry, findtime, bantime). You enable a jail with enabled = true. One fail2ban instance can run many jails at once, each protecting a different service.
What is the difference between bantime, findtime and maxretry?
These three settings define when and how long an IP is banned. maxretry is the number of failures allowed; findtime is the time window (in seconds) in which those failures must occur to trigger a ban; and bantime is how long the ban lasts. For example maxretry = 5, findtime = 600, bantime = 3600 bans an IP for one hour once it fails five times within ten minutes. Set bantime to -1 for a permanent ban.
How to create a custom fail2ban jail?
Add a new section to /etc/fail2ban/jail.local with a header like [myservice], set enabled = true, point logpath at the log to watch, set filter to a filter defined under /etc/fail2ban/filter.d/, and choose your port and ban thresholds. If no built-in filter matches your service, create a filter file with a failregex. This generator lets you pick "Custom" and type your own filter name to produce the jail block.
How to protect SSH with fail2ban?
Enable the [sshd] jail. Set filter = sshd, logpath = /var/log/auth.log (or /var/log/secure on RHEL/CentOS), port = ssh, and a strict policy such as maxretry = 3, findtime = 600, bantime = 3600. Restart fail2ban and verify with sudo fail2ban-client status sshd. This bans IPs that repeatedly fail SSH logins, dramatically reducing brute-force noise.
How to protect Nginx with fail2ban?
Use the nginx-http-auth filter to protect HTTP Basic Auth areas, or nginx-limit-req to ban IPs that trip Nginx rate limiting. Point logpath at /var/log/nginx/error.log (for auth failures) or access.log, set port = 80,443, and tune maxretry/findtime/bantime. For login-form abuse you typically need a custom filter matching your application's failure log lines.
How to whitelist an IP in fail2ban?
Add the IP (or CIDR range) to the ignoreip directive, which can be set per-jail or in the [DEFAULT] section of jail.local. Always include your own management IPs and the loopback addresses, e.g. ignoreip = 127.0.0.1/8 ::1 203.0.113.5. IPs listed here are never banned, which protects you from locking yourself out.
What is a permanent ban in fail2ban?
A permanent ban is configured by setting bantime = -1. The offending IP stays blocked until you manually unban it or restart fail2ban without persistence. Permanent bans are useful for services under constant attack, but combine them with a solid ignoreip list and consider fail2ban's persistent ban database so bans survive restarts.
How to check if fail2ban is working?
Run sudo systemctl status fail2ban to confirm the service is active, then sudo fail2ban-client status to list enabled jails, and sudo fail2ban-client status sshd (or any jail name) to see currently banned IPs and totals. You can also watch /var/log/fail2ban.log to see bans and unbans happen in real time.
How to unban an IP in fail2ban?
Use sudo fail2ban-client set <jailname> unbanip <IP>, for example sudo fail2ban-client set sshd unbanip 203.0.113.5. To avoid banning a trusted address in future, also add it to the ignoreip directive. Restarting fail2ban clears all current bans unless you have persistent bans configured.
Where do I put the generated jail.local configuration?
Paste it into /etc/fail2ban/jail.local (create the file if it does not exist). Never edit jail.conf directly — jail.local overrides it and survives package upgrades. After saving, run sudo systemctl restart fail2ban (or reload) and confirm the jail is active with sudo fail2ban-client status.

Related Tools