I already run fail2ban on my home server, and it does its job well: it watches the mail and SSH logs, and it bans brute-forcers within a second or two. But fail2ban has two structural limits. It’s reactive — an attacker has to hit my server, and fail long enough to trip a jail, before anything happens. And it’s local — every server learns about every attacker from scratch, on its own.
[Read More]Hardening a Self-Hosted Mail Server: fail2ban, Postfix, and Dovecot
Update (2026-06-05): the
[Read More]action = firewallcmd-rich-rulesshown below has since been replaced with fail2ban’s nativenftablesaction. With ~2000 banned addresses the firewalld variant needed 90 seconds to stop and was killed withSIGABRT— it removes each ban as an individual rich rule, and any that firewalld had already dropped during a reload wait for a timeout. See the homelab guide for the current configuration. Everything else here still applies.