fail2ban for Nginx

fail2ban reads your Nginx access log, counts matching requests per IP, and adds a firewall rule once a threshold is passed. It complements rate limiting: Nginx slows bursts, fail2ban removes persistent offenders.

Three parts

A filter defines what a bad request looks like as a regex, a jail ties a filter to a log file with maxretry, findtime and bantime, and an action does the banning.

Tune before you ban

Test the filter with fail2ban-regex against a real log first. A regex that is too broad will ban legitimate users.

fail2ban-regex /var/log/nginx/access.log /etc/fail2ban/filter.d/nginx-probe.conf

Open the fail2ban jail generator

Frequently asked questions

Does fail2ban work behind a CDN?

Only if the log records the real client IP. Otherwise it will ban the CDN address.

Guides