Update (2026-06-05): the
[Read More]action = firewallcmd-rich-rulesshown below has since been replaced with fail2ban’s nativenftablesaction. With ~2000 banned addresses the firewalld variant needed 90 seconds to stop and was killed withSIGABRT— it removes each ban as an individual rich rule, and any that firewalld had already dropped during a reload wait for a timeout. See the homelab guide for the current configuration. Everything else here still applies.