How to Protect SSH with Fail2ban on Ubuntu 24.04

October 6, 2026

Table of Contents

Any VPS with a public IP will see automated SSH brute-force attempts within minutes of booting. Fail2ban watches your logs, and when an IP fails to log in too many times it bans that address at the firewall for a while. This guide installs and configures Fail2ban to protect SSH on Ubuntu 24.04 LTS.

Fail2ban reads the auth log and bans IPs that exceed the retry limit

Prerequisites

Step 1 — Install Fail2ban

sudo apt update
sudo apt install -y fail2ban

Step 2 — Create a local configuration

Never edit jail.conf directly (package updates overwrite it). Put your settings in jail.local, which overrides the defaults:

sudo nano /etc/fail2ban/jail.local

Step 3 — Configure the SSH jail

Add the following. Replace 203.0.113.10 with your own IP so you can never be locked out:

[DEFAULT]
# Ban for 1 hour after 5 failures within 10 minutes
bantime  = 1h
findtime = 10m
maxretry = 5
# Never ban these addresses (localhost + your trusted IP)
ignoreip = 127.0.0.1/8 ::1 203.0.113.10

[sshd]
enabled = true

On Ubuntu 24.04 the sshd jail reads the systemd journal automatically, so no log path is required.

Step 4 — Enable and start Fail2ban

sudo systemctl enable --now fail2ban
sudo systemctl status fail2ban

Step 5 — Check the jail

sudo fail2ban-client status
sudo fail2ban-client status sshd

The sshd status shows currently failed and banned IP addresses.

Step 6 — Unban an address

Accidentally banned yourself or a colleague? Release the IP instantly:

sudo fail2ban-client set sshd unbanip 203.0.113.55

Step 7 — Escalate repeat offenders (optional)

Enable the recidive jail to hand out much longer bans to IPs that keep coming back after shorter bans — a simple way to shut down persistent attackers.

Next steps

Conclusion

Fail2ban now turns the constant background noise of brute-force attempts into automatic, temporary bans — no manual log-watching required. Combined with a UFW firewall and key-only SSH, your VPS presents a very small, well-defended attack surface.

Views: 36

Need help with this topic? Ask our AI Assistant!

Assistant focuses on: How to Protect SSH with Fail2ban on Ubuntu 24.04

Hello! How can I help you with "How to Protect SSH with Fail2ban on Ubuntu 24.04"?
Share on
Facebook
Twitter
LinkedIn
Print

Search

Category

Tags

VPSie Cloud service

Fast and Secure Cloud VPS Service

Try FREE
For a month

The First 1 orders gets free discount today! Try Sign up on VPSie to get a chance to get the discount.