\

Ask HN: Alternatives to Fail2ban?

6 points - last Friday at 12:48 PM


I'm administering a small number of Linux servers that run an ssh server exposed to the Internet. I usually connect using a cryptographic key, but I still allow password authentication in case of trouble (perhaps I'm being overly cautious). I've been using fail2ban with good results, but I'm annoyed at having to install a Python interpreter on every server.

Is there an alternative to fail2ban that is just a single binary? It doesn't need to have all of the features of fail2ban, blocking dictionary attacks against ssh is all I need.

  • f30e3dfed1c9

    last Saturday at 2:52 AM

    > an ssh server exposed to the Internet. I... still allow password authentication in case of trouble

    You gotta get over that eventually and really, the sooner the better.

    • laruss5

      last Friday at 6:56 PM

      sshguard is exactly this - single C binary, no interpreter needed. It tails your logs (journalctl/syslog) and bans offenders via iptables/nftables/pf. No Python, no dependencies beyond the firewall backend: https://www.sshguard.net/

        • BlueRoguesDevel

          last Saturday at 2:27 PM

          How did I miss this? I have a stack begging to try this out, and for the same reasons as OP. Thank you.

          • jech

            last Friday at 9:25 PM

            One hour later, it appears that sshguard is working fine. It's structured as a dozen binaries or so, but it has no dependencies. I haven't done any CPU usage measurements, but I haven't seen it appear in top's output.

            • jech

              last Friday at 8:12 PM

              > sshguard is exactly this

              Thanks. I've replaced fail2ban with sshguard on one machine, we'll see how it goes.

          • Bender

            last Friday at 12:50 PM

            This isn't for everyone and it will block old ssh libraries (libssh, go ssh, etc...), windows and others but if you only have OpenSSH 10+ and that's all you connect with then this method [1] has worked well for me. It gets botters to exclude my nodes that expose SSH on purpose (such as public anonymous SFTP). If trying it out test from an out of band console first.

            Edit: I should add, there will still be some syslog entries, but that can be filtered out using regex filters in rsyslog one so desired. Only do so once it is confirmed most of the brute forcing has stopped.

            [1] - https://nochan.net/b/Internet-Crap/20260108-Confuse-Some-SSH...

            • aborsy

              yesterday at 4:01 PM

              Disable password authentication and ignore the noise.

              • brazukadev

                yesterday at 7:27 PM

                there is fail2zig seems to be exactly what you looking for

                https://fail2zig.com

                • rishabhyadav_

                  last Saturday at 10:50 PM

                  [dead]

                  • atmosx

                    last Friday at 4:43 PM

                    [dead]