開始輸入,可搜尋發票、服務、域名、工單,以及 更多...
只要伺服器有公網 IP,幾分鐘內就會有機器人開始猜測 SSH 密碼,網站也會被掃描後臺和高頻請求。Fail2ban 會持續分析日誌,發現某個 IP 在短時間內多次失敗或請求過快,就自動呼叫防火牆封禁它。本文介紹在 Debian/Ubuntu 與 Rocky Linux/AlmaLinux 上安裝 Fail2ban、編寫 jail.local、開啟 sshd 防暴力破解、用 nginx-limit-req 與 nginx-http-auth 保護網站、配合 ufw/firewalld,以及解封和設定白名單。
Debian/Ubuntu 直接從系統源安裝,同時安裝 python3-systemd,以便從 systemd 日誌讀取 SSH 登入記錄(Debian 12 起預設沒有 /var/log/auth.log)。Rocky/AlmaLinux 的 Fail2ban 位於 EPEL 倉庫,fail2ban-firewalld 包會自動讓它使用 firewalld 封禁。
# Debian / Ubuntu
apt update
apt install -y fail2ban python3-systemd
# Rocky Linux / AlmaLinux (EPEL)
dnf install -y epel-release
dnf install -y fail2ban fail2ban-firewalld
systemctl enable --now fail2ban
fail2ban-client version
不要修改 jail.conf,升級時會被覆蓋;所有自定義都寫在 jail.local。下面的配置表示:10 分鐘內失敗 3 次即封禁 1 小時,屢犯者封禁時間遞增,最長一週。若已修改 SSH 埠(參見“修改 SSH 埠與密碼”教程),請把 port 改為實際埠,否則封禁規則不會作用在真正的埠上。
# Never edit jail.conf (it is overwritten on upgrade); use jail.local
cat > /etc/fail2ban/jail.local <<'EOF'
[DEFAULT]
# Your own IPs are never banned (office/home IP, monitoring, other servers)
ignoreip = 127.0.0.1/8 ::1 198.51.100.20 203.0.113.0/24
bantime = 1h
findtime = 10m
maxretry = 5
# Repeat offenders get longer bans, up to one week
bantime.increment = true
bantime.maxtime = 1w
[sshd]
enabled = true
# use your custom port if you changed it, e.g. port = 2222
port = ssh
backend = systemd
maxretry = 3
EOF
fail2ban-client -t # test the configuration
systemctl restart fail2ban
fail2ban-client status
fail2ban-client status sshd
banaction 決定 Fail2ban 用什麼方式封禁。Ubuntu/Debian 使用 ufw 時設為 ufw;Rocky/AlmaLinux 安裝 fail2ban-firewalld 後已自動使用 firewalld 富規則;未使用這兩種防火牆時可用 nftables-multiport。三者只選一個,寫入 jail.local 的 [DEFAULT] 段後重啟 Fail2ban(防火牆基礎配置見“Linux 防火牆”教程)。
# Debian / Ubuntu with ufw - add to [DEFAULT] in /etc/fail2ban/jail.local
banaction = ufw
# Rocky / AlmaLinux with firewalld - set automatically by fail2ban-firewalld
# (/etc/fail2ban/jail.d/00-firewalld.conf), or explicitly:
banaction = firewallcmd-rich-rules
# Plain nftables without ufw/firewalld
banaction = nftables-multiport
# Check that bans really reach the firewall
ufw status numbered | head
firewall-cmd --list-rich-rules
nft list ruleset | grep -A5 f2b
nginx-limit-req 依賴 Nginx 的 limit_req 模組:請求超過速率時,Nginx 會在 error.log 寫入 “limiting requests” 日誌,Fail2ban 據此封禁。nginx-http-auth 則監控 Basic Auth 密碼錯誤,適合保護後臺目錄。速率請按業務調整,避免誤傷正常訪客。
# /etc/nginx/nginx.conf, inside http { }
limit_req_zone $binary_remote_addr zone=perip:10m rate=10r/s;
# inside the server { } or location { } you want to protect
limit_req zone=perip burst=20 nodelay;
# protected area with basic auth (optional)
location /admin/ {
auth_basic "Restricted";
auth_basic_user_file /etc/nginx/.htpasswd;
}
nginx -t && systemctl reload nginx
在 jail.d 中單獨建一個 Nginx 配置檔案更便於管理。啟用前先用 fail2ban-regex 測試過濾規則能否匹配日誌,有匹配結果才說明規則生效。寶塔面板的 Nginx 日誌路徑不同,請按實際路徑修改 logpath。
cat > /etc/fail2ban/jail.d/nginx.local <<'EOF'
[nginx-http-auth]
enabled = true
port = http,https
logpath = /var/log/nginx/error.log
[nginx-limit-req]
enabled = true
port = http,https
logpath = /var/log/nginx/error.log
findtime = 1m
maxretry = 10
bantime = 2h
EOF
# Check that the filter matches lines in your log
fail2ban-regex /var/log/nginx/error.log /etc/fail2ban/filter.d/nginx-limit-req.conf
fail2ban-client reload
fail2ban-client status nginx-limit-req
誤封時可按 jail 解封或全部解封。addignoreip 只在本次執行中有效,永久白名單需寫入 jail.local 的 ignoreip 後 reload。如果把自己封了無法 SSH 登入,可換一個網路(如手機熱點)登入解封,或通過客戶中心提供的控制臺(如有)操作,也可以提交工單協助。
fail2ban-client status sshd # list banned IPs
fail2ban-client set sshd unbanip 198.51.100.20 # unban from one jail
fail2ban-client unban 198.51.100.20 # unban from all jails
fail2ban-client unban --all # clear every ban
fail2ban-client set sshd addignoreip 198.51.100.20 # whitelist until restart
# Permanent whitelist: add the IP to "ignoreip" in jail.local, then
fail2ban-client reload
tail -f /var/log/fail2ban.log # watch bans live
常見於 Debian 12 及以後:系統不再生成 auth.log。在 sshd 段設定 backend = systemd 並安裝 python3-systemd 即可。執行 fail2ban-client -t 可以看到具體錯誤。
通常是 banaction 與正在使用的防火牆不一致,或 port 與實際 SSH 埠不同。檢查步驟 3 的命令中是否出現了對應規則。
不能。Fail2ban 只能降低暴力破解的速度,最有效的做法是停用密碼登入、改用 SSH 金鑰,兩者配合使用效果最好。
如果按以上步驟操作後問題仍未解決,請提交工單聯絡 IMIDC 7×24 技術支援,並附上伺服器 IP、系統版本、執行過的命令和完整報錯資訊,方便工程師快速定位。