**How to Install and Configure Fail2Ban on CyberPanel (AlmaLinux 8.10, CyberPanel 2.4.3)**
---
### ✅ Step 1: Install Fail2Ban
```bash
dnf install epel-release -y
dnf install fail2ban -y
```
### ✅ Step 2: Enable and Start firewalld (Required for Banning)
```bash
systemctl enable firewalld --now
firewall-cmd --state # confirms firewalld is active
```
### ✅ Step 3: Enable and Start Fail2Ban
```bash
systemctl enable fail2ban --now
```
### ✅ Step 4: Create `jail.local` for SSHD
Edit or create the jail configuration file:
```bash
nano /etc/fail2ban/jail.local
```
Paste the following:
```ini
[DEFAULT]
banaction = firewallcmd-rich-rules
backend = systemd
ignoreip = 127.0.0.1/8 ::1
findtime = 600
bantime = 3600
maxretry = 5
[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/secure
maxretry = 3
bantime = 600
findtime = 600
```
Save with `CTRL+X`, then `Y`, then `Enter`.
### ✅ Step 5: Test the Configuration
Check the status of Fail2Ban:
```bash
systemctl status fail2ban
```
List enabled jails:
```bash
fail2ban-client status
```
Check SSHD jail details:
```bash
fail2ban-client status sshd
```
### ✅ Step 6: Test Banning Manually
```bash
fail2ban-client set sshd banip 1.2.3.4
firewall-cmd --list-rich-rules
```
---
### 🚨 Extra Tips: CyberPanel Integration
CyberPanel shows SSH attack logs visually, but you must rely on Fail2Ban to ban the IPs.
Verify the following:
* `/var/log/secure` contains SSH logs.
* SSHD filter works:
```bash
fail2ban-regex /var/log/secure /etc/fail2ban/filter.d/sshd.conf
```
---
## ✅ Import Previously Blocked IPs from CyberPanel Firewall to Fail2Ban
### Create the Import Script
```bash
nano /root/import-banned-ips.sh
```
Paste this:
```bash
#!/bin/bash
JAIL="sshd"
IPS=(
125.91.106.241
92.118.39.87
116.103.227.168
92.118.39.62
89.110.87.132
220.80.197.180
86.54.25.130
80.94.95.112
80.94.95.15
123.58.213.127
213.139.72.208
20.54.64.50
36.108.171.28
202.39.251.216
116.193.190.8
114.96.87.140
118.122.147.195
154.83.15.132
220.205.122.62
203.66.14.161
103.215.80.141
147.50.227.79
35.210.61.208
61.188.205.76
101.47.72.59
150.241.246.148
92.55.83.15
98.66.154.229
193.151.149.140
43.139.232.36
62.210.97.97
78.159.98.70
209.38.23.83
181.2.151.236
211.219.22.213
103.48.84.147
177.220.176.63
122.156.167.62
107.148.176.145
191.220.115.223
193.32.162.157
144.48.240.124
116.98.175.44
116.105.214.33
43.156.115.5
14.225.220.107
92.205.21.23
120.48.162.75
45.148.10.240
50.84.211.204
120.28.197.159
172.245.11.43
69.49.247.178
103.82.240.194
221.229.218.50
207.167.66.226
218.51.148.194
14.103.161.184
103.59.94.155
45.116.77.25
103.215.81.209
92.118.39.92
185.93.89.118
192.227.247.40
27.119.7.6
103.189.235.176
158.51.124.56
41.58.186.130
147.50.103.212
14.103.243.87
124.44.117.106
103.56.115.23
190.111.211.81
202.157.176.210
64.235.33.145
4.154.223.182
195.178.110.125
111.180.199.183
185.155.62.232
14.103.118.106
45.159.221.129
101.89.182.189
186.96.166.237
14.63.196.175
111.173.104.178
14.103.90.30
92.118.39.71
124.164.237.56
103.120.227.88
119.246.15.94
119.28.86.241
14.103.170.169
47.81.8.111
139.150.83.88
27.254.235.13
172.208.24.217
39.109.104.252
1.202.223.2
103.187.147.35
123.253.162.254
)
for ip in "${IPS[@]}"; do
echo "banning $ip in jail $JAIL"
fail2ban-client set "$JAIL" banip "$ip"
done
```
Make it executable:
```bash
chmod +x /root/import-banned-ips.sh
```
Run it:
```bash
/root/import-banned-ips.sh
```
### ✅ Verify Bans Were Imported
```bash
fail2ban-client status sshd
```
You should see something like:
```
|- Currently banned: 92
`- Banned IP list: 125.91.106.241 92.118.39.87 ...
```
### ♻ Optional: Clean Up Old Manual Rules from firewalld
```bash
for ip in "${IPS[@]}"; do
firewall-cmd --permanent --remove-rich-rule="rule family=ipv4 source address=$ip drop"
done
firewall-cmd --reload
```
---
## ✅ Final Checklist: Ensure Auto-Banning is Working
1. **Fail2Ban is Running**
```bash
systemctl status fail2ban
```
Should say `active (running)`.
2. **SSHD Jail is Enabled**
```bash
fail2ban-client status
```
You should see `sshd` listed.
3. **Correct Log Path**
Make sure you're using:
```ini
logpath = /var/log/secure
```
4. **Valid Ban Action**
```ini
banaction = firewallcmd-rich-rules
```
Or:
```ini
banaction = firewallcmd-ipset
```
5. **Filter Is Matching**
Run:
```bash
fail2ban-regex /var/log/secure /etc/fail2ban/filter.d/sshd.conf
```
This should show matched log lines.
Once all of the above is set, new attackers are automatically detected and banned by Fail2Ban with no manual work required!
Comments
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|👍
/👎
0 B
|0 👍
/0 👎