About fail2ban
Fail2Ban is an intrusion prevention daemon that watches log files, such as the authentication log, for repeated failed login attempts. When an address crosses a configured threshold, it adds firewall rules to reject new connections from that IP for a set period, which reduces brute-force noise against services.
It works out of the box with many standard logs, including those of sshd and Apache, and can be configured to read any log file for any error pattern you choose. IPv6 address matching has been supported since version 0.10. The README is frank about the limits: banning reduces the rate of failed attempts but cannot remove the risk of weak authentication, so you should still use two-factor or key-based authentication for important services.
Fail2Ban is written in Python and runs on Linux, macOS and BSD systems. Its license is listed as 'Other' on GitHub, and topics mention GPLv2, so confirm the terms. Documentation includes a manpage, wiki and developer guides. It is a long-standing, lightweight tool on self-managed servers, favored by sysadmins protecting SSH, web and mail services.
Key features
- Scans logs for repeated failed logins
- Bans offending IPs through firewall rules
- Ready-made filters for sshd and Apache
- Configurable ban durations and patterns
- IPv6 address support
- Works with any log file you point it at
Good fit for
- →Blocking SSH brute-force attempts
- →Protecting web and mail servers from abuse
- →Adding a lightweight intrusion-prevention layer
- Built with
- Python
- Tags
- security
- intrusion-prevention
- firewall
- linux
- python
- ssh
- brute-force
- log-monitoring
- sysadmin
fail2ban: questions and answers
- What is fail2ban used for?
- fail2ban is a Python daemon that reads log files and temporarily bans IP addresses with too many failed login attempts by updating firewall rules. It is a good fit for blocking SSH brute-force attempts, protecting web and mail servers from abuse, and adding a lightweight intrusion-prevention layer.
- Is fail2ban open source?
- Yes. fail2ban is open source under a custom licence. Its source code is on GitHub at fail2ban/fail2ban and is written mainly in Python.
- Is fail2ban free?
- Yes. fail2ban is open source, so the software itself is free to use under the terms of its own licence.
- Can I self-host fail2ban?
- Yes. fail2ban can be self-hosted on your own server or infrastructure; there is no official hosted version.
- What are some alternatives to fail2ban?
- Similar open-source tools in the Security category include step-ca, DefectDojo and OPNsense. SaaS products in the same category include Check Point, Fortinet and Palo Alto Networks.
- Is fail2ban actively maintained?
- Yes. The most recent commit to fail2ban was on 28 September 2026, and the latest release is 1.1.1, published on 15 August 2026. The project has 19k stars on GitHub.
Open-source alternatives to fail2ban
See all
step-ca
Security
🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certi
Apache-2.0vs Entrust★ 8.9k
DefectDojo
Security
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
BSD-3-Clausevs Tenable★ 5k
OPNsense
Security
OPNsense GUI, API and systems backend
BSD-2-Clausevs Fortinet★ 4.7k
IVRE
Security
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to
GPL-3.0vs Shodan★ 4.2kfwknop
Security
Single Packet Authorization > Port Knocking
GPL-2.0★ 1.5k
CISO Assistant
Security
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & A
OSSvs Vanta★ 4.5k
SaaS alternatives to fail2ban
See all
Check Point
Security
Network firewalls, cloud and endpoint security from an Israeli security vendor
SaaS
Fortinet
Security
FortiGate firewalls and a broad security fabric for network, cloud and endpoints
SaaS
Palo Alto Networks
Security
Network, cloud and endpoint security vendor selling firewalls, SASE and SOC tools
SaaS
Sophos
Security
Endpoint, firewall and managed detection and response services for businesses
SaaS
Abnormal Security
Security
Behavior-based cloud email security that blocks phishing and account takeover
SaaS
Adverse Monitor
Security
Cyber threat intelligence tool that watches the dark web for incident claims naming your company
SaaS

