sudo systemctl enable --now psad
| IP | Threat | Packets |
|---|---|---|
198.51.100.11 |
5 | 87 |
198.51.100.16 |
4 | 2,085 |
198.51.100.12 |
4 | 1,259 |
198.51.100.14 |
4 | 235 |
198.51.100.13 |
3 | 2,392 |
198.51.100.15 |
3 | 195 |
Fail2ban watches services and reacts to failed logins. It cannot see someone who never tries to log in — an address that sweeps your ports looking for something to talk to leaves no failed authentication behind, so no jail fires. PSAD fills that gap by reading iptables log entries for traffic that was dropped, and grading what it finds.
This page shows the addresses PSAD has flagged, the danger level it assigned each one, how many packets they sent and which ports they went after. The danger level runs from one to five and is worth reading in context: a single probe against a closed port is background noise on any public address, while a methodical sweep across hundreds of ports from one source usually precedes an attempt at whatever it finds open.
PSAD needs a logging rule in your firewall to see anything at all, which is the usual reason it reports nothing on a fresh install. The UFW page in this panel shows whether that logging is in place.