I’ve used fail2ban in the past on Ubuntu, and it was very easy to setup.

Apparently on Debian, there is no /var/log/auth.log, and it does not use iptables, so fail2ban is not seeing the failed login attempts and jailing the purp.

Has anyone set this up successfully before? I see suggestions online to set backend = systemd, but this does not seem to be fixing the issue for me.

  • @rootOP
    link
    29 months ago

    Oooh, good point. I’m not even sure if I should be using this with cert only based auth

    It does usually not make sense to use fail2ban with e.g sshd when only public key authentication or similar is enabled.