History of Fail2ban - Testing and Monitoring
<h2>Check jail status</h2>
<pre>
# All jails overview
fail2ban-client status
# Specific jail detail
fail2ban-client status nginx-404
fail2ban-client status nginx-botsearch
fail2ban-client status recidive
</pre>
<h2>Manual ban/unban testing</h2>
<pre>
# Ban a test IP
fail2ban-client set nginx-404 banip 1.2.3.4
# Confirm firewalld has the rule
firewall-cmd --list-rich-rules
# Check email arrived in support@ folder
# Unban test IP
fail2ban-client set nginx-404 unbanip 1.2.3.4
# Confirm rule removed
firewall-cmd --list-rich-rules
</pre>
<h2>Check ban times are correct</h2>
<pre>
fail2ban-client get nginx-404 bantime
fail2ban-client get nginx-botsearch bantime
fail2ban-client get recidive bantime
fail2ban-client get recidive findtime
</pre>
<h2>Live monitoring</h2>
<pre>
# Watch fail2ban log in real time
tail -f /var/log/fail2ban.log
# Current banned IPs across all jails
fail2ban-client status nginx-404 | grep &quot;Banned IP&quot;
fail2ban-client status nginx-botsearch | grep &quot;Banned IP&quot;
fail2ban-client status recidive | grep &quot;Banned IP&quot;
# Count total bans
fail2ban-client status nginx-404 | grep &quot;Total banned&quot;
</pre>
<h2>Check firewalld rules</h2>
<pre>
# All current rich rules (fail2ban entries)
firewall-cmd --list-rich-rules
# Count active bans
firewall-cmd --list-rich-rules | wc -l
# Check specific IP is blocked
firewall-cmd --list-rich-rules | grep 1.2.3.4
</pre>
<h2>Recidive specific</h2>
<pre>
# Recidive watches fail2ban.log for repeat offenders
# Ban pattern: banned 3+ times in 24 hours = 1 week ban
# Test by checking known repeat offender
fail2ban-client status recidive
# Recidive restores bans after restart - no email on restore
# Only emails on NEW bans
# To force a new ban notification:
fail2ban-client set recidive unbanip 216.244.66.243
fail2ban-client set recidive banip 216.244.66.243
</pre>
<h2>Regex testing</h2>
<pre>
# Test a filter against actual log
fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/nginx-404.conf | tail -5
# Test recidive filter
fail2ban-regex /var/log/fail2ban.log /etc/fail2ban/filter.d/recidive.conf | tail -5
</pre>
<h2>Troubleshooting</h2>
<pre>
# fail2ban not banning despite log entries
# &rarr; Check filter regex matches log format
fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/nginx-404.conf
# Bans not blocking traffic
# &rarr; Check banaction is firewallcmd not iptables
grep banaction /etc/fail2ban/jail.conf
# &rarr; Verify firewalld rules being created
firewall-cmd --list-rich-rules
# No emails from recidive
# &rarr; Recidive restores bans silently on restart
# &rarr; Only new bans trigger email
# &rarr; Test with manual banip
# jail.local overrides not working
# &rarr; Edit jail.conf directly, copy to webstack
# Time suffixes (1w, 1d) supported from fail2ban 0.11+
# &rarr; Verify: fail2ban-client version
</pre>
<h2>Status check script</h2>
<pre>
#!/bin/bash
# /etc/webstack/scripts/fail2ban-status.sh
echo &quot;=== Fail2ban Status ===&quot;
fail2ban-client status
echo &quot;&quot;
echo &quot;=== Active Bans ===&quot;
for jail in nginx-404 nginx-botsearch recidive; do
echo &quot;--- $jail ---&quot;
fail2ban-client status $jail | grep -E &quot;Currently banned|Total banned|Banned IP&quot;
done
echo &quot;&quot;
echo &quot;=== Firewalld Rules ===&quot;
echo &quot;Total rules: $(firewall-cmd --list-rich-rules | wc -l)&quot;
firewall-cmd --list-rich-rules | tail -5
echo &quot;(showing last 5)&quot;
</pre>
<p><em>Developed with [Claude AI](https://claude.ai) assistance - Anthropic - May 2026</em></p>
<pre>
# All jails overview
fail2ban-client status
# Specific jail detail
fail2ban-client status nginx-404
fail2ban-client status nginx-botsearch
fail2ban-client status recidive
</pre>
<h2>Manual ban/unban testing</h2>
<pre>
# Ban a test IP
fail2ban-client set nginx-404 banip 1.2.3.4
# Confirm firewalld has the rule
firewall-cmd --list-rich-rules
# Check email arrived in support@ folder
# Unban test IP
fail2ban-client set nginx-404 unbanip 1.2.3.4
# Confirm rule removed
firewall-cmd --list-rich-rules
</pre>
<h2>Check ban times are correct</h2>
<pre>
fail2ban-client get nginx-404 bantime
fail2ban-client get nginx-botsearch bantime
fail2ban-client get recidive bantime
fail2ban-client get recidive findtime
</pre>
<h2>Live monitoring</h2>
<pre>
# Watch fail2ban log in real time
tail -f /var/log/fail2ban.log
# Current banned IPs across all jails
fail2ban-client status nginx-404 | grep &quot;Banned IP&quot;
fail2ban-client status nginx-botsearch | grep &quot;Banned IP&quot;
fail2ban-client status recidive | grep &quot;Banned IP&quot;
# Count total bans
fail2ban-client status nginx-404 | grep &quot;Total banned&quot;
</pre>
<h2>Check firewalld rules</h2>
<pre>
# All current rich rules (fail2ban entries)
firewall-cmd --list-rich-rules
# Count active bans
firewall-cmd --list-rich-rules | wc -l
# Check specific IP is blocked
firewall-cmd --list-rich-rules | grep 1.2.3.4
</pre>
<h2>Recidive specific</h2>
<pre>
# Recidive watches fail2ban.log for repeat offenders
# Ban pattern: banned 3+ times in 24 hours = 1 week ban
# Test by checking known repeat offender
fail2ban-client status recidive
# Recidive restores bans after restart - no email on restore
# Only emails on NEW bans
# To force a new ban notification:
fail2ban-client set recidive unbanip 216.244.66.243
fail2ban-client set recidive banip 216.244.66.243
</pre>
<h2>Regex testing</h2>
<pre>
# Test a filter against actual log
fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/nginx-404.conf | tail -5
# Test recidive filter
fail2ban-regex /var/log/fail2ban.log /etc/fail2ban/filter.d/recidive.conf | tail -5
</pre>
<h2>Troubleshooting</h2>
<pre>
# fail2ban not banning despite log entries
# &rarr; Check filter regex matches log format
fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/nginx-404.conf
# Bans not blocking traffic
# &rarr; Check banaction is firewallcmd not iptables
grep banaction /etc/fail2ban/jail.conf
# &rarr; Verify firewalld rules being created
firewall-cmd --list-rich-rules
# No emails from recidive
# &rarr; Recidive restores bans silently on restart
# &rarr; Only new bans trigger email
# &rarr; Test with manual banip
# jail.local overrides not working
# &rarr; Edit jail.conf directly, copy to webstack
# Time suffixes (1w, 1d) supported from fail2ban 0.11+
# &rarr; Verify: fail2ban-client version
</pre>
<h2>Status check script</h2>
<pre>
#!/bin/bash
# /etc/webstack/scripts/fail2ban-status.sh
echo &quot;=== Fail2ban Status ===&quot;
fail2ban-client status
echo &quot;&quot;
echo &quot;=== Active Bans ===&quot;
for jail in nginx-404 nginx-botsearch recidive; do
echo &quot;--- $jail ---&quot;
fail2ban-client status $jail | grep -E &quot;Currently banned|Total banned|Banned IP&quot;
done
echo &quot;&quot;
echo &quot;=== Firewalld Rules ===&quot;
echo &quot;Total rules: $(firewall-cmd --list-rich-rules | wc -l)&quot;
firewall-cmd --list-rich-rules | tail -5
echo &quot;(showing last 5)&quot;
</pre>
<p><em>Developed with [Claude AI](https://claude.ai) assistance - Anthropic - May 2026</em></p>
