ESC

开始输入,可搜索发票、服务、域名、工单,以及 更多...

搜索... Ctrl+K
Linux 服务器

Fail2ban 安装配置教程:防止 SSH 暴力破解与网站 CC 攻击(Debian/Ubuntu/Rocky)

6 个步骤 11 分钟阅读 3 次阅读 0
本文目录

只要服务器有公网 IP,几分钟内就会有机器人开始猜测 SSH 密码,网站也会被扫描后台和高频请求。Fail2ban 会持续分析日志,发现某个 IP 在短时间内多次失败或请求过快,就自动调用防火墙封禁它。本文介绍在 Debian/Ubuntu 与 Rocky Linux/AlmaLinux 上安装 Fail2ban、编写 jail.local、开启 sshd 防暴力破解、用 nginx-limit-req 与 nginx-http-auth 保护网站、配合 ufw/firewalld,以及解封和设置白名单。

开始前请先把你自己的公网 IP 加入白名单(步骤 2 的 ignoreip),并保持一个已登录的 SSH 会话,避免测试时把自己封掉。

步骤 1:安装 Fail2ban

Debian/Ubuntu 直接从系统源安装,同时安装 python3-systemd,以便从 systemd 日志读取 SSH 登录记录(Debian 12 起默认没有 /var/log/auth.log)。Rocky/AlmaLinux 的 Fail2ban 位于 EPEL 仓库,fail2ban-firewalld 包会自动让它使用 firewalld 封禁。

# Debian / Ubuntu
apt update
apt install -y fail2ban python3-systemd

# Rocky Linux / AlmaLinux (EPEL)
dnf install -y epel-release
dnf install -y fail2ban fail2ban-firewalld

systemctl enable --now fail2ban
fail2ban-client version

步骤 2:编写 jail.local 并开启 sshd 防 SSH 暴力破解

不要修改 jail.conf,升级时会被覆盖;所有自定义都写在 jail.local。下面的配置表示:10 分钟内失败 3 次即封禁 1 小时,屡犯者封禁时间递增,最长一周。若已修改 SSH 端口(参见“修改 SSH 端口与密码”教程),请把 port 改为实际端口,否则封禁规则不会作用在真正的端口上。

# Never edit jail.conf (it is overwritten on upgrade); use jail.local
cat > /etc/fail2ban/jail.local <<'EOF'
[DEFAULT]
# Your own IPs are never banned (office/home IP, monitoring, other servers)
ignoreip = 127.0.0.1/8 ::1 198.51.100.20 203.0.113.0/24
bantime  = 1h
findtime = 10m
maxretry = 5
# Repeat offenders get longer bans, up to one week
bantime.increment = true
bantime.maxtime   = 1w

[sshd]
enabled  = true
# use your custom port if you changed it, e.g. port = 2222
port     = ssh
backend  = systemd
maxretry = 3
EOF

fail2ban-client -t            # test the configuration
systemctl restart fail2ban
fail2ban-client status
fail2ban-client status sshd

步骤 3:配置 banaction,配合 ufw 或 firewalld

banaction 决定 Fail2ban 用什么方式封禁。Ubuntu/Debian 使用 ufw 时设为 ufw;Rocky/AlmaLinux 安装 fail2ban-firewalld 后已自动使用 firewalld 富规则;未使用这两种防火墙时可用 nftables-multiport。三者只选一个,写入 jail.local 的 [DEFAULT] 段后重启 Fail2ban(防火墙基础配置见“Linux 防火墙”教程)。

# Debian / Ubuntu with ufw - add to [DEFAULT] in /etc/fail2ban/jail.local
banaction = ufw

# Rocky / AlmaLinux with firewalld - set automatically by fail2ban-firewalld
# (/etc/fail2ban/jail.d/00-firewalld.conf), or explicitly:
banaction = firewallcmd-rich-rules

# Plain nftables without ufw/firewalld
banaction = nftables-multiport

# Check that bans really reach the firewall
ufw status numbered | head
firewall-cmd --list-rich-rules
nft list ruleset | grep -A5 f2b

步骤 4:为 Nginx 开启限速与认证日志

nginx-limit-req 依赖 Nginx 的 limit_req 模块:请求超过速率时,Nginx 会在 error.log 写入 “limiting requests” 日志,Fail2ban 据此封禁。nginx-http-auth 则监控 Basic Auth 密码错误,适合保护后台目录。速率请按业务调整,避免误伤正常访客。

# /etc/nginx/nginx.conf, inside http { }
limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;

# inside the server { } or location { } you want to protect
limit_req zone=perip burst=20 nodelay;

# protected area with basic auth (optional)
location /admin/ {
    auth_basic           "Restricted";
    auth_basic_user_file /etc/nginx/.htpasswd;
}

nginx -t && systemctl reload nginx

步骤 5:启用 nginx-limit-req 与 nginx-http-auth 封禁规则

在 jail.d 中单独建一个 Nginx 配置文件更便于管理。启用前先用 fail2ban-regex 测试过滤规则能否匹配日志,有匹配结果才说明规则生效。宝塔面板的 Nginx 日志路径不同,请按实际路径修改 logpath。

cat > /etc/fail2ban/jail.d/nginx.local <<'EOF'
[nginx-http-auth]
enabled  = true
port     = http,https
logpath  = /var/log/nginx/error.log

[nginx-limit-req]
enabled  = true
port     = http,https
logpath  = /var/log/nginx/error.log
findtime = 1m
maxretry = 10
bantime  = 2h
EOF

# Check that the filter matches lines in your log
fail2ban-regex /var/log/nginx/error.log /etc/fail2ban/filter.d/nginx-limit-req.conf

fail2ban-client reload
fail2ban-client status nginx-limit-req
如果网站使用了 CDN,Nginx 日志中记录的是 CDN 节点 IP,直接封禁会导致大量正常用户无法访问。请先在 Nginx 中用 real_ip 还原访客真实 IP(参见“Nginx 反向代理”教程),或在 CDN 端做限速。

步骤 6:Fail2ban 解封 IP 与设置白名单

误封时可按 jail 解封或全部解封。addignoreip 只在本次运行中有效,永久白名单需写入 jail.local 的 ignoreip 后 reload。如果把自己封了无法 SSH 登录,可换一个网络(如手机热点)登录解封,或通过客户中心提供的控制台(如有)操作,也可以提交工单协助。

fail2ban-client status sshd                      # list banned IPs
fail2ban-client set sshd unbanip 198.51.100.20   # unban from one jail
fail2ban-client unban 198.51.100.20              # unban from all jails
fail2ban-client unban --all                      # clear every ban

fail2ban-client set sshd addignoreip 198.51.100.20   # whitelist until restart
# Permanent whitelist: add the IP to "ignoreip" in jail.local, then
fail2ban-client reload

tail -f /var/log/fail2ban.log                    # watch bans live

常见问题

Fail2ban 启动失败,提示找不到日志文件?

常见于 Debian 12 及以后:系统不再生成 auth.log。在 sshd 段设置 backend = systemd 并安装 python3-systemd 即可。执行 fail2ban-client -t 可以看到具体错误。

状态显示有封禁,但对方仍能连接?

通常是 banaction 与正在使用的防火墙不一致,或 port 与实际 SSH 端口不同。检查步骤 3 的命令中是否出现了对应规则。

Fail2ban 能替代密钥登录吗?

不能。Fail2ban 只能降低暴力破解的速度,最有效的做法是禁用密码登录、改用 SSH 密钥,两者配合使用效果最好。

如果按以上步骤操作后问题仍未解决,请提交工单联系 IMIDC 7×24 技术支持,并附上服务器 IP、系统版本、执行过的命令和完整报错信息,方便工程师快速定位。

这篇文章有帮助吗?

相关教程