## Inspect and control fail2ban bans

# Is fail2ban running?
sudo fail2ban-client ping

# Overall status and the active jails
sudo fail2ban-client status

# Status of one jail, with currently banned addresses
sudo fail2ban-client status sshd

# Just the currently banned list
sudo fail2ban-client get sshd banned

# Is a specific address banned?
sudo fail2ban-client get sshd banip 198.51.100.7

# Ban an address by hand
sudo fail2ban-client set sshd banip 198.51.100.7

# Ban several at once
sudo fail2ban-client set sshd banip 198.51.100.7 203.0.113.9

# Unban an address
sudo fail2ban-client set sshd unbanip 198.51.100.7

# Unban an address from every jail
sudo fail2ban-client unban 198.51.100.7

# Unban everything, in every jail
sudo fail2ban-client unban --all

# Current ban time for a jail
sudo fail2ban-client get sshd bantime

# Change the ban time at runtime
sudo fail2ban-client set sshd bantime 3600

# Current retry threshold
sudo fail2ban-client get sshd maxretry

# Change it at runtime
sudo fail2ban-client set sshd maxretry 3

# The window in which failures are counted
sudo fail2ban-client get sshd findtime

# Addresses that are never banned
sudo fail2ban-client get sshd ignoreip

# Add your own address to the ignore list
sudo fail2ban-client set sshd addignoreip 203.0.113.10

# Remove an address from the ignore list
sudo fail2ban-client set sshd delignoreip 203.0.113.10

# Which log files a jail watches
sudo fail2ban-client get sshd logpath

# The filter a jail uses
sudo fail2ban-client get sshd filter

# The actions a jail takes
sudo fail2ban-client get sshd actions

# Start a jail
sudo fail2ban-client start sshd

# Stop a jail
sudo fail2ban-client stop sshd

# Reload one jail after editing its config
sudo fail2ban-client reload sshd

# Reload everything
sudo fail2ban-client reload

# Reload without losing current bans
sudo fail2ban-client reload --restart

# Test a filter against a log file before enabling it
sudo fail2ban-regex /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf

# Test and print every matched line
sudo fail2ban-regex --print-all-matched /var/log/auth.log /etc/fail2ban/filter.d/sshd.conf

# Raise the log level for debugging
sudo fail2ban-client set loglevel DEBUG

# Back to normal
sudo fail2ban-client set loglevel INFO

# Where the local configuration belongs (never edit jail.conf)
sudo tee /etc/fail2ban/jail.local > /dev/null <<'EOF'
[DEFAULT]
bantime  = 1h
findtime = 10m
maxretry = 5
ignoreip = 127.0.0.1/8 203.0.113.10

[sshd]
enabled = true
EOF

# Apply that configuration
sudo systemctl restart fail2ban

# Follow what fail2ban is doing
sudo tail -f /var/log/fail2ban.log

# Recent bans from the log
sudo grep -i ' ban ' /var/log/fail2ban.log | tail

# Count bans per address
sudo awk '/ Ban /{print $NF}' /var/log/fail2ban.log | sort | uniq -c | sort -rn | head

# The firewall rules fail2ban created
sudo nft list ruleset | grep -A5 f2b

# The failed logins it is reacting to
sudo grep 'Failed password' /var/log/auth.log | tail
