# fail2ban local settings, deployed by install.sh. Debian's defaults-debian.conf # enables the sshd jail; this file decides how it bans. [DEFAULT] # Never ban loopback or the private LAN ranges: five typos from the LAN must not # lock the admin out for an hour. Trade-off: a compromised LAN host is never banned. ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 bantime = 1h findtime = 10m maxretry = 5 banaction = nftables banaction_allports = nftables[type=allports] [sshd] enabled = true # Read the journal directly: works with or without /var/log/auth.log (rsyslog). backend = systemd journalmatch = _SYSTEMD_UNIT=ssh.service + _COMM=sshd # Ban the offender on every port, so the port sshd listens on is irrelevant. The # previous server's jail banned port 22 only while sshd listened on 337. banaction = %(banaction_allports)s