开始输入,可搜索发票、服务、域名、工单,以及 更多...
只要服务器有公网 IP,几分钟内就会有机器人开始猜测 SSH 密码,网站也会被扫描后台和高频请求。Fail2ban 会持续分析日志,发现某个 IP 在短时间内多次失败或请求过快,就自动调用防火墙封禁它。本文介绍在 Debian/Ubuntu 与 Rocky Linux/AlmaLinux 上安装 Fail2ban、编写 jail.local、开启 sshd 防暴力破解、用 nginx-limit-req 与 nginx-http-auth 保护网站、配合 ufw/firewalld,以及解封和设置白名单。
Debian/Ubuntu 直接从系统源安装,同时安装 python3-systemd,以便从 systemd 日志读取 SSH 登录记录(Debian 12 起默认没有 /var/log/auth.log)。Rocky/AlmaLinux 的 Fail2ban 位于 EPEL 仓库,fail2ban-firewalld 包会自动让它使用 firewalld 封禁。
# Debian / Ubuntu
apt update
apt install -y fail2ban python3-systemd
# Rocky Linux / AlmaLinux (EPEL)
dnf install -y epel-release
dnf install -y fail2ban fail2ban-firewalld
systemctl enable --now fail2ban
fail2ban-client version
不要修改 jail.conf,升级时会被覆盖;所有自定义都写在 jail.local。下面的配置表示:10 分钟内失败 3 次即封禁 1 小时,屡犯者封禁时间递增,最长一周。若已修改 SSH 端口(参见“修改 SSH 端口与密码”教程),请把 port 改为实际端口,否则封禁规则不会作用在真正的端口上。
# Never edit jail.conf (it is overwritten on upgrade); use jail.local
cat > /etc/fail2ban/jail.local <<'EOF'
[DEFAULT]
# Your own IPs are never banned (office/home IP, monitoring, other servers)
ignoreip = 127.0.0.1/8 ::1 198.51.100.20 203.0.113.0/24
bantime = 1h
findtime = 10m
maxretry = 5
# Repeat offenders get longer bans, up to one week
bantime.increment = true
bantime.maxtime = 1w
[sshd]
enabled = true
# use your custom port if you changed it, e.g. port = 2222
port = ssh
backend = systemd
maxretry = 3
EOF
fail2ban-client -t # test the configuration
systemctl restart fail2ban
fail2ban-client status
fail2ban-client status sshd
banaction 决定 Fail2ban 用什么方式封禁。Ubuntu/Debian 使用 ufw 时设为 ufw;Rocky/AlmaLinux 安装 fail2ban-firewalld 后已自动使用 firewalld 富规则;未使用这两种防火墙时可用 nftables-multiport。三者只选一个,写入 jail.local 的 [DEFAULT] 段后重启 Fail2ban(防火墙基础配置见“Linux 防火墙”教程)。
# Debian / Ubuntu with ufw - add to [DEFAULT] in /etc/fail2ban/jail.local
banaction = ufw
# Rocky / AlmaLinux with firewalld - set automatically by fail2ban-firewalld
# (/etc/fail2ban/jail.d/00-firewalld.conf), or explicitly:
banaction = firewallcmd-rich-rules
# Plain nftables without ufw/firewalld
banaction = nftables-multiport
# Check that bans really reach the firewall
ufw status numbered | head
firewall-cmd --list-rich-rules
nft list ruleset | grep -A5 f2b
nginx-limit-req 依赖 Nginx 的 limit_req 模块:请求超过速率时,Nginx 会在 error.log 写入 “limiting requests” 日志,Fail2ban 据此封禁。nginx-http-auth 则监控 Basic Auth 密码错误,适合保护后台目录。速率请按业务调整,避免误伤正常访客。
# /etc/nginx/nginx.conf, inside http { }
limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;
# inside the server { } or location { } you want to protect
limit_req zone=perip burst=20 nodelay;
# protected area with basic auth (optional)
location /admin/ {
auth_basic "Restricted";
auth_basic_user_file /etc/nginx/.htpasswd;
}
nginx -t && systemctl reload nginx
在 jail.d 中单独建一个 Nginx 配置文件更便于管理。启用前先用 fail2ban-regex 测试过滤规则能否匹配日志,有匹配结果才说明规则生效。宝塔面板的 Nginx 日志路径不同,请按实际路径修改 logpath。
cat > /etc/fail2ban/jail.d/nginx.local <<'EOF'
[nginx-http-auth]
enabled = true
port = http,https
logpath = /var/log/nginx/error.log
[nginx-limit-req]
enabled = true
port = http,https
logpath = /var/log/nginx/error.log
findtime = 1m
maxretry = 10
bantime = 2h
EOF
# Check that the filter matches lines in your log
fail2ban-regex /var/log/nginx/error.log /etc/fail2ban/filter.d/nginx-limit-req.conf
fail2ban-client reload
fail2ban-client status nginx-limit-req
误封时可按 jail 解封或全部解封。addignoreip 只在本次运行中有效,永久白名单需写入 jail.local 的 ignoreip 后 reload。如果把自己封了无法 SSH 登录,可换一个网络(如手机热点)登录解封,或通过客户中心提供的控制台(如有)操作,也可以提交工单协助。
fail2ban-client status sshd # list banned IPs
fail2ban-client set sshd unbanip 198.51.100.20 # unban from one jail
fail2ban-client unban 198.51.100.20 # unban from all jails
fail2ban-client unban --all # clear every ban
fail2ban-client set sshd addignoreip 198.51.100.20 # whitelist until restart
# Permanent whitelist: add the IP to "ignoreip" in jail.local, then
fail2ban-client reload
tail -f /var/log/fail2ban.log # watch bans live
常见于 Debian 12 及以后:系统不再生成 auth.log。在 sshd 段设置 backend = systemd 并安装 python3-systemd 即可。执行 fail2ban-client -t 可以看到具体错误。
通常是 banaction 与正在使用的防火墙不一致,或 port 与实际 SSH 端口不同。检查步骤 3 的命令中是否出现了对应规则。
不能。Fail2ban 只能降低暴力破解的速度,最有效的做法是禁用密码登录、改用 SSH 密钥,两者配合使用效果最好。
如果按以上步骤操作后问题仍未解决,请提交工单联系 IMIDC 7×24 技术支持,并附上服务器 IP、系统版本、执行过的命令和完整报错信息,方便工程师快速定位。