Three jails enabled, two of them watching log files that moved when the services were containerised. A jail watching a file that does not exist reports zero failures,…
Enabling every bundled jail produces bans from filters matching log formats your software does not emit, and a config nobody trusts enough to tune. fail2ban-regex against a real…
SSH and HTTP basic auth are covered by shipped filters. A brute force against the application’s own login form is invisible to both, because it is a 200…
fail2ban is installed for SSH and left there, but the same brute force runs against every HTTP login on the box — a WordPress admin, a staging basic-auth…