ESC

開始輸入,可搜尋發票、服務、域名、工單,以及 更多...

搜尋... Ctrl+K
Linux 伺服器

Fail2ban 安裝配置教程:防止 SSH 暴力破解與網站 CC 攻擊(Debian/Ubuntu/Rocky)

6 個步驟 11 分鐘閱讀 19 次閱讀 0
本文目錄

只要伺服器有公網 IP,幾分鐘內就會有機器人開始猜測 SSH 密碼,網站也會被掃描後臺和高頻請求。Fail2ban 會持續分析日誌,發現某個 IP 在短時間內多次失敗或請求過快,就自動呼叫防火牆封禁它。本文介紹在 Debian/Ubuntu 與 Rocky Linux/AlmaLinux 上安裝 Fail2ban、編寫 jail.local、開啟 sshd 防暴力破解、用 nginx-limit-req 與 nginx-http-auth 保護網站、配合 ufw/firewalld,以及解封和設定白名單。

開始前請先把你自己的公網 IP 加入白名單(步驟 2 的 ignoreip),並保持一個已登入的 SSH 會話,避免測試時把自己封掉。

步驟 1:安裝 Fail2ban

Debian/Ubuntu 直接從系統源安裝,同時安裝 python3-systemd,以便從 systemd 日誌讀取 SSH 登入記錄(Debian 12 起預設沒有 /var/log/auth.log)。Rocky/AlmaLinux 的 Fail2ban 位於 EPEL 倉庫,fail2ban-firewalld 包會自動讓它使用 firewalld 封禁。

# Debian / Ubuntu
apt update
apt install -y fail2ban python3-systemd

# Rocky Linux / AlmaLinux (EPEL)
dnf install -y epel-release
dnf install -y fail2ban fail2ban-firewalld

systemctl enable --now fail2ban
fail2ban-client version

步驟 2:編寫 jail.local 並開啟 sshd 防 SSH 暴力破解

不要修改 jail.conf,升級時會被覆蓋;所有自定義都寫在 jail.local。下面的配置表示:10 分鐘內失敗 3 次即封禁 1 小時,屢犯者封禁時間遞增,最長一週。若已修改 SSH 埠(參見“修改 SSH 埠與密碼”教程),請把 port 改為實際埠,否則封禁規則不會作用在真正的埠上。

# Never edit jail.conf (it is overwritten on upgrade); use jail.local
cat > /etc/fail2ban/jail.local <<'EOF'
[DEFAULT]
# Your own IPs are never banned (office/home IP, monitoring, other servers)
ignoreip = 127.0.0.1/8 ::1 198.51.100.20 203.0.113.0/24
bantime  = 1h
findtime = 10m
maxretry = 5
# Repeat offenders get longer bans, up to one week
bantime.increment = true
bantime.maxtime   = 1w

[sshd]
enabled  = true
# use your custom port if you changed it, e.g. port = 2222
port     = ssh
backend  = systemd
maxretry = 3
EOF

fail2ban-client -t            # test the configuration
systemctl restart fail2ban
fail2ban-client status
fail2ban-client status sshd

步驟 3:配置 banaction,配合 ufw 或 firewalld

banaction 決定 Fail2ban 用什麼方式封禁。Ubuntu/Debian 使用 ufw 時設為 ufw;Rocky/AlmaLinux 安裝 fail2ban-firewalld 後已自動使用 firewalld 富規則;未使用這兩種防火牆時可用 nftables-multiport。三者只選一個,寫入 jail.local 的 [DEFAULT] 段後重啟 Fail2ban(防火牆基礎配置見“Linux 防火牆”教程)。

# Debian / Ubuntu with ufw - add to [DEFAULT] in /etc/fail2ban/jail.local
banaction = ufw

# Rocky / AlmaLinux with firewalld - set automatically by fail2ban-firewalld
# (/etc/fail2ban/jail.d/00-firewalld.conf), or explicitly:
banaction = firewallcmd-rich-rules

# Plain nftables without ufw/firewalld
banaction = nftables-multiport

# Check that bans really reach the firewall
ufw status numbered | head
firewall-cmd --list-rich-rules
nft list ruleset | grep -A5 f2b

步驟 4:為 Nginx 開啟限速與認證日誌

nginx-limit-req 依賴 Nginx 的 limit_req 模組:請求超過速率時,Nginx 會在 error.log 寫入 “limiting requests” 日誌,Fail2ban 據此封禁。nginx-http-auth 則監控 Basic Auth 密碼錯誤,適合保護後臺目錄。速率請按業務調整,避免誤傷正常訪客。

# /etc/nginx/nginx.conf, inside http { }
limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;

# inside the server { } or location { } you want to protect
limit_req zone=perip burst=20 nodelay;

# protected area with basic auth (optional)
location /admin/ {
    auth_basic           "Restricted";
    auth_basic_user_file /etc/nginx/.htpasswd;
}

nginx -t && systemctl reload nginx

步驟 5:啟用 nginx-limit-req 與 nginx-http-auth 封禁規則

在 jail.d 中單獨建一個 Nginx 配置檔案更便於管理。啟用前先用 fail2ban-regex 測試過濾規則能否匹配日誌,有匹配結果才說明規則生效。寶塔面板的 Nginx 日誌路徑不同,請按實際路徑修改 logpath。

cat > /etc/fail2ban/jail.d/nginx.local <<'EOF'
[nginx-http-auth]
enabled  = true
port     = http,https
logpath  = /var/log/nginx/error.log

[nginx-limit-req]
enabled  = true
port     = http,https
logpath  = /var/log/nginx/error.log
findtime = 1m
maxretry = 10
bantime  = 2h
EOF

# Check that the filter matches lines in your log
fail2ban-regex /var/log/nginx/error.log /etc/fail2ban/filter.d/nginx-limit-req.conf

fail2ban-client reload
fail2ban-client status nginx-limit-req
如果網站使用了 CDN,Nginx 日誌中記錄的是 CDN 節點 IP,直接封禁會導致大量正常使用者無法訪問。請先在 Nginx 中用 real_ip 還原訪客真實 IP(參見“Nginx 反向代理”教程),或在 CDN 端做限速。

步驟 6:Fail2ban 解封 IP 與設定白名單

誤封時可按 jail 解封或全部解封。addignoreip 只在本次執行中有效,永久白名單需寫入 jail.local 的 ignoreip 後 reload。如果把自己封了無法 SSH 登入,可換一個網路(如手機熱點)登入解封,或通過客戶中心提供的控制臺(如有)操作,也可以提交工單協助。

fail2ban-client status sshd                      # list banned IPs
fail2ban-client set sshd unbanip 198.51.100.20   # unban from one jail
fail2ban-client unban 198.51.100.20              # unban from all jails
fail2ban-client unban --all                      # clear every ban

fail2ban-client set sshd addignoreip 198.51.100.20   # whitelist until restart
# Permanent whitelist: add the IP to "ignoreip" in jail.local, then
fail2ban-client reload

tail -f /var/log/fail2ban.log                    # watch bans live

常見問題

Fail2ban 啟動失敗,提示找不到日誌檔案?

常見於 Debian 12 及以後:系統不再生成 auth.log。在 sshd 段設定 backend = systemd 並安裝 python3-systemd 即可。執行 fail2ban-client -t 可以看到具體錯誤。

狀態顯示有封禁,但對方仍能連線?

通常是 banaction 與正在使用的防火牆不一致,或 port 與實際 SSH 埠不同。檢查步驟 3 的命令中是否出現了對應規則。

Fail2ban 能替代金鑰登入嗎?

不能。Fail2ban 只能降低暴力破解的速度,最有效的做法是停用密碼登入、改用 SSH 金鑰,兩者配合使用效果最好。

如果按以上步驟操作後問題仍未解決,請提交工單聯絡 IMIDC 7×24 技術支援,並附上伺服器 IP、系統版本、執行過的命令和完整報錯資訊,方便工程師快速定位。

這篇文章有幫助嗎?

相關教程