fail2ban – Automatyczne aktualizacje bezpieczeństwa

Fail2ban to otwartoźródłowy system zapobiegania włamaniom, który chroni serwery Linux przed atakami siłowymi

# apt install -y unattended-upgrades apt-listchanges

# dpkg-reconfigure -plow unattended-upgrades

Debian 13 domyślnie nie ma rsyslog, więc nie istnieje /var/log/auth.log. fail2ban musi czytać z journald:

# apt install -y fail2ban python3-systemd

Plik /etc/fail2ban/jail.local:

[DEFAULT]
backend = systemd
bantime = 1h
findtime = 10m
maxretry = 5

[sshd]
enabled = true
# systemctl enable --now fail2ban
# fail2ban-client status sshd