trustmebro.reviews

fail2ban

Software Tool · Self-hosted & homelab software · 10 mentions · 2 subreddits · discussed in r/homelab, r/webdev

Reddit take

Not enough linked mention summaries yet; the source excerpts below are the evidence.

Pros

  • I have fail2ban setup on each client with a custom script so a ban is propagated to the proxy too.
  • Fail2ban is great. A good combo is CrowdSec and fail2ban
  • For some services I additionally use Basic Auth; this is monitored by fail2ban/crowdsec, and failed attempts get banned.
  • If one of your services has a login page and you don't have MFA, they could potentially brute force it (which is why a lot of people recommend fail2ban).
  • fail2ban with a very strict rules, etc.

Cons

  • Security: crowdsec ori fail2ban. But neither will help in case of a 0 day exploit like the recent react shit.
  • fail2ban is also something you should check out. It watches for failed login attempts and firewalls them.
  • I no longer need fail2ban as Cloudflare will take care of all of that as part of the WAF.

Sentiment

7 positive (70%) · 3 mixed (30%) · 0 negative (0%)

Trust + time weighted score: +70% · raw score 70%

What redditors said (10 of 10)

I have fail2ban setup on each client with a custom script so a ban is propagated to the proxy too.
positive · u/b****4 · r/homelab · comment · Dec 27, 2025 · open on Reddit ↗
Fail2ban is great. A good combo is CrowdSec and fail2ban
positive · u/1****e · r/homelab · comment · Dec 27, 2025 · open on Reddit ↗
For some services I additionally use Basic Auth; this is monitored by fail2ban/crowdsec, and failed attempts get banned.
positive · u/C****6 · r/homelab · comment · Dec 27, 2025 · open on Reddit ↗
Security: crowdsec ori fail2ban. But neither will help in case of a 0 day exploit like the recent react shit.
mixed · u/A****D · r/homelab · comment · Dec 17, 2025 · open on Reddit ↗
fail2ban is also something you should check out. It watches for failed login attempts and firewalls them.
mixed · u/T****d · r/homelab · comment · Nov 1, 2025 · open on Reddit ↗
If one of your services has a login page and you don't have MFA, they could potentially brute force it (which is why a lot of people recommend fail2ban).
positive · u/b****7 · r/homelab · comment · Jul 22, 2025 · open on Reddit ↗
fail2ban with a very strict rules, etc.
positive · u/I****5 · r/homelab · Jul 22, 2025 · open on Reddit ↗
Hardening linux with SSH, IPtables, Fail2ban, etc..
positive · u/D****C · r/homelab · comment · Jul 2, 2025 · open on Reddit ↗
Have you looked at CrowdSec or Fail2Ban? IIRC these security tools might help you to nail down malicious actors that are knocking up too often at your door.
positive · u/B****7 · r/webdev · comment · Feb 10, 2025 · open on Reddit ↗
I no longer need fail2ban as Cloudflare will take care of all of that as part of the WAF.
mixed · u/T****e · r/webdev · Feb 8, 2025 · open on Reddit ↗

Compare

Related