Fail2ban Jail Generator
Create a custom jail.local configuration for SSH, Apache, Nginx, mail and more — tune ban policy and copy it straight to your server.
Advertisement
Important — Use at Your Own Risk
This tool generates configuration for reference and learning purposes only.
Before applying any generated config to a production server:
- Test in a staging/development environment first
- Understand each option before applying
- Take a full backup of existing configuration
- Verify compatibility with your OS version
- Wrong security settings can lock you out of your server
SysAdmin Tools is not responsible for server outages, data loss or security issues caused by applying generated configurations.
Failed attempts before ban
Time window to count failures
How long to ban the IP
IPs never banned (space separated)
[sshd] enabled = true port = 22 filter = sshd logpath = /var/log/auth.log maxretry = 5 findtime = 600 bantime = 3600 action = %(action_)s ignoreip = 127.0.0.1/8 ::1
Advertisement
Advertisement
This fail2ban jail generator builds a ready-to-paste jail.local configuration for any service you want to protect from brute-force attacks — SSH, Apache, Nginx, Postfix, Dovecot, WordPress and more. Pick a service, tune the ban settings, and copy the generated jail block straight into /etc/fail2ban/jail.local.
Fail2ban is an intrusion-prevention tool that scans log files for repeated authentication failures and bans the offending IP with iptables (or nftables/firewalld) for a configurable period. The hard part is remembering the exact directive names and sensible values for maxretry, findtime and bantime. This fail2ban config generator fills in the correct filter, port and logpath for each service automatically, so you get a correct fail2ban jail without reading the manual.
Everything runs in your browser — no data is sent anywhere. Use it to create a fail2ban ssh jail configuration, a fail2ban nginx jail config, or a custom jail with your own filter name, then apply it and reload fail2ban.
How to Use the Fail2ban Jail Generator
- 1
Choose the service to protect
Select SSH, Apache, Nginx, Postfix, Dovecot, WordPress or a custom filter. The port, filter name and log path are auto-filled with sensible defaults for that service.
- 2
Adjust the jail settings
Confirm the enabled toggle, port, filter and logpath. Override any of them if your server uses non-standard paths or ports.
- 3
Set the ban policy
Set maxretry (failures allowed), findtime (the window to count them in) and bantime (how long to ban). Use the unit dropdowns for minutes/hours/days, or tick permanent ban for bantime = -1.
- 4
Choose an action and whitelist
Pick a ban action — plain ban, or ban plus whois/mail/log — and add any IPs to ignoreip so you never lock yourself out.
- 5
Copy and apply
Click Generate, copy the jail block into /etc/fail2ban/jail.local, then run sudo systemctl restart fail2ban and check it with fail2ban-client status.
Understanding the Generated jail.local
filter (a regex that recognises a failed login in a log), a logpath (the file to watch), a set of thresholds (maxretry, findtime, bantime), and an action (how to ban). Jails live in jail.local, which overrides the package-supplied jail.conf so your settings survive updates.
The three numbers are the heart of a jail. maxretry is how many matching failures are allowed before a ban. findtime is the sliding window (in seconds) those failures must occur within. bantime is how long the IP stays banned — a positive number of seconds, or -1 for a permanent ban. For example, maxretry = 5, findtime = 600, bantime = 3600 means "five failures within ten minutes earns a one-hour ban".
The action controls what happens on a ban. %(action_)s simply bans the IP; %(action_mw)s also emails a whois report; %(action_mwl)s emails the whois report plus the offending log lines. Always set ignoreip to include your own trusted IPs (and 127.0.0.1/8 ::1) so fail2ban never bans you.| Field | Description |
|---|---|
| [jailname] | The jail section header, e.g. [sshd]. Names the jail and groups its directives. |
| enabled | true activates the jail; false leaves it defined but inactive. |
| port | The port(s) the ban action blocks, e.g. ssh or 80,443. |
| filter | The filter (regex ruleset) under /etc/fail2ban/filter.d used to detect failures. |
| logpath | The log file fail2ban scans for authentication failures. |
| maxretry | Number of failures within findtime before the IP is banned. |
| findtime | The window, in seconds, over which failures are counted. |
| bantime | How long a ban lasts in seconds; -1 means a permanent ban. |
| ignoreip | Space-separated IPs/CIDRs that are never banned — include your own IP. |
Advertisement
Common Fail2ban Jail Use Cases
Stop SSH brute-force attacks
Generate an [sshd] jail watching /var/log/auth.log that bans an IP after a handful of failed logins. This is the single most useful fail2ban jail on any internet-facing Linux server.
Protect a web login (WordPress, admin panels)
Create a jail using the Nginx or Apache auth filter, or a custom WordPress filter, to ban IPs hammering wp-login.php or a mod_auth protected area.
Harden mail services
Add Postfix SMTP and Dovecot IMAP jails to ban clients repeatedly failing SMTP AUTH or IMAP login — a common source of credential-stuffing on mail servers.
Permanent bans for persistent offenders
Set bantime to -1 to permanently ban IPs for sensitive services, while keeping a generous ignoreip list so your own addresses are always allowed.
Fail2ban Jail Generator — Frequently Asked Questions
What is fail2ban and how does it work?
What is a fail2ban jail?
What is the difference between bantime, findtime and maxretry?
How to create a custom fail2ban jail?
How to protect SSH with fail2ban?
How to protect Nginx with fail2ban?
How to whitelist an IP in fail2ban?
What is a permanent ban in fail2ban?
How to check if fail2ban is working?
How to unban an IP in fail2ban?
Where do I put the generated jail.local configuration?
Related Tools
SSH Hardening Generator
Lock down sshd_config to reduce the attack surface fail2ban defends.
Security Headers
Audit the HTTP security headers your web server sends.
Port Checker
Confirm which ports are exposed before and after banning rules apply.
Nginx Config Generator
Generate the Nginx server block whose logs your jails will watch.