Security Monitor

Security Monitor
Real server events Real attacks caught by Fail2ban — including persistent repeat offenders (recidive jail)
Real bans/hour
114
Real bans today
2113
Actually blocked
54,171
Active jails
26
Preventive block (ipsum) Public blocklist of malicious IPs (ipsum) dropped at the firewall; updated daily
IPset ipsum
118,295
3.32 MB
Active
Attack timeline
Protection overview
System
Load (1/5/15) 1.66 (1.66 / 1.45 / 1.58)
Total 8
Fail2ban Active
IPset ipsum Active 118,295 IPs
Bans in 24h
bans/hour 114
Today 2113
Yesterday 1,745
This month 14,802
IPset 118,295
Fail2ban jails
Jail Active Total Failed attempts
HTTP-GET-DOS 146 848 6
PORTSCAN 227 998 14
RECIDIVE 52,883 53,403 17
RECIDIVE-PERMANENT 112 828 10
SSHD 803 1,518 24
Recent bans
2026-10-11 15:53:15 recidive ⊘ 198.51.100.21
2026-10-11 15:31:52 nginx-http-auth ⊘ 192.0.2.43
2026-10-11 16:32:05 recidive ⊘ 192.0.2.41
2026-10-11 16:12:07 recidive ⊘ 198.51.100.18
2026-10-11 17:04:04 nginx-http-auth ⊘ 198.51.100.19
2026-10-11 17:05:54,151 fail2ban.actions [826]: NOTICE [recidive] Unban 198.51.100.15
2026-10-11 15:11:47 portscan ⊘ 198.51.100.18
2026-10-11 16:22:50 recidive ⊘ 192.0.2.41
2026-10-11 15:42:33,763 fail2ban.actions [826]: NOTICE [recidive] Unban 198.51.100.15
2026-10-11 16:38:57 recidive ⊘ 198.51.100.22
2026-10-11 14:10:26 recidive ⊘ 198.51.100.35
2026-10-11 18:33:30 recidive ⊘ 192.0.2.31
2026-10-11 16:09:43 recidive ⊘ 198.51.100.24
2026-10-11 16:43:46 recidive ⊘ 192.0.2.33
2026-10-11 17:20:22 recidive ⊘ 198.51.100.22
2026-10-11 16:28:38 portscan ⊘ 198.51.100.35
2026-10-11 18:00:59 sshd ⊘ 198.51.100.26
2026-10-11 13:41:56 recidive ⊘ 192.0.2.47
2026-10-11 18:21:25 recidive ⊘ 198.51.100.25
2026-10-11 14:22:06 recidive ⊘ 198.51.100.20

A Fail2ban web interface instead of fail2ban-client

Fail2ban works quietly and reports almost nothing unless you ask it. Checking a server means running fail2ban-client status, reading the list of jails, then running the command again for each jail in turn. With a dozen jails configured that is a dozen commands to answer one question: is anything hitting this box right now?

This page answers it in one screen. Every configured jail is listed with the number of currently banned addresses and the total it has caught since the service started, so a jail that is doing nothing is as visible as one that is working hard. Below that come the individual bans with the address, the jail that caught it and when the ban expires.

If you are deciding which jails are worth running, start with sshd, add the authentication endpoint of whatever web application you host, and only then reach for the exotic filters. A jail that never fires costs nothing but tells you nothing either.

A quiet service is a good thing only for as long as somebody looks in on it. Fail2ban will not send a note saying it banned three hundred addresses overnight, and it will not send one saying it banned none — and the second is the more worrying of the two: usually it means a jail is reading the wrong log file. The daily summary for the machine is assembled by Logwatch, and bans land in it along with everything else.