| Jail | Active | Total | Failed attempts |
|---|---|---|---|
| HTTP-GET-DOS | 146 | 848 | 6 |
| PORTSCAN | 227 | 998 | 14 |
| RECIDIVE | 52,883 | 53,403 | 17 |
| RECIDIVE-PERMANENT | 112 | 828 | 10 |
| SSHD | 803 | 1,518 | 24 |
Fail2ban works quietly and reports almost nothing unless you ask it. Checking a server means running fail2ban-client status, reading the list of jails, then running the command again for each jail in turn. With a dozen jails configured that is a dozen commands to answer one question: is anything hitting this box right now?
This page answers it in one screen. Every configured jail is listed with the number of currently banned addresses and the total it has caught since the service started, so a jail that is doing nothing is as visible as one that is working hard. Below that come the individual bans with the address, the jail that caught it and when the ban expires.
If you are deciding which jails are worth running, start with sshd, add the authentication endpoint of whatever web application you host, and only then reach for the exotic filters. A jail that never fires costs nothing but tells you nothing either.
A quiet service is a good thing only for as long as somebody looks in on it. Fail2ban will not send a note saying it banned three hundred addresses overnight, and it will not send one saying it banned none — and the second is the more worrying of the two: usually it means a jail is reading the wrong log file. The daily summary for the machine is assembled by Logwatch, and bans land in it along with everything else.