Fail2Ban is a security tool that analyzes your server’s log files and automatically blocks IP addresses after repeated failed login attempts. In Plesk, you can activate Fail2Ban with just a few clicks and configure how strict the protection should be for each service (SSH, FTP, mail). This article shows you how to set it up and which settings are advisable.
What Fail2Ban exactly does
Fail2Ban monitors the log files of services such as SSH, FTP, Dovecot, and Plesk itself. When a set number of failed attempts occurs within a certain time period, the corresponding IP address is temporarily blocked at the firewall level. This prevents an attacker from endlessly trying passwords, and reduces unnecessary load on your server.
Activating Fail2Ban in Plesk
Log in to Plesk
Open your Plesk panel and log in with your administrator account.
Go to Tools & Settings
Click on « Tools & Settings » in the left menu and find the « Fail2Ban » section (sometimes located under Security or Server Management).
Install if necessary
If Fail2Ban isn’t already present, install the corresponding Plesk extension via the extensions catalog.
Enable the service
Set Fail2Ban to « Active » and check that the status shows green.
Activate jails per service
Enable the filters for the services you want to protect, such as SSH, FTP, Dovecot (mail), and Plesk itself.
Configuring jail settings
For each jail, you can configure three important values:
- Max retry: the number of failed attempts before an IP is blocked.
- Find time: the period within which these attempts are counted.
- Ban time: how long the IP remains blocked.
For SSH, it’s wise to be stricter than the default values, for example by using a lower max retry and a longer ban time. For mail and FTP services, you can set things somewhat more leniently, depending on how many users connect from varying networks.
Whitelist and exceptions
Add fixed IP addresses, such as your office or home network, to the whitelist so you never accidentally lock yourself out. In Plesk, you’ll find this option in the Fail2Ban settings under « Ignore IP ». Check blocked addresses via the log file or the status overview in Plesk, so you can see if a legitimate user has been incorrectly blocked.
A properly secured server is especially important if you also run business email hosting, since mail accounts are a popular target for brute-force attacks. If you’re considering switching to a provider with tighter default security, check out the options to switch to Tandata.
Frequently Asked Questions
Can Fail2Ban block legitimate users?
Yes, if someone enters an incorrect password multiple times. Prevent this by using SSH keys and whitelisting fixed IP addresses.
How can I see which IP addresses are blocked?
Via Plesk under Tools & Settings in the Fail2Ban section, or via SSH with the command tail -f /var/log/fail2ban.log.
Does Fail2Ban work together with LiteSpeed?
Yes, Fail2Ban can function as an additional layer alongside LiteSpeed’s built-in security options without any noticeable effect on performance.
Can I extend Fail2Ban for specific applications?
Yes, you can create custom filters for, for example, WordPress logins. This requires manual configuration, but Plesk also offers ready-made filters for commonly used services.
Conclusion
Fail2Ban in Plesk is a simple yet effective way to protect your server against brute-force attacks. By tailoring the jail settings to your situation and using a whitelist, you keep your server secure without hindering legitimate users. For more configuration tips, check out our knowledge base.