#498164 [fail2ban] Allow repeated attacker to be blocked for increasingly longer times

Package:
fail2ban
Source:
fail2ban
Submitter:
Ariel Garcia
Date:
2026-09-07 15:37:03 UTC
Severity:
wishlist
Tags:
#498164#5
Date:
2008-09-07 17:39:04 UTC
From:
To:
--- Please enter the report below this line. ---

It would be nice to be able to block repeated offenders for increasingly
longer periods of time:

currently  fail2ban blocks an IP for  "bantime" after "maxretry"
connections. Then the IP is unblocked. If that same IP tries again to
connect after having been unblocked, a new  ban for a duration
of "bantime" seconds is put in place.

But it would be great if the second time an IP starts to "attack" it gets
blocked for a longer period of time, the third time for an even longer
period etc.

As a similar example, in another machine i use pure iptables + recent rules
to ban an IP connecting
   4    times in 30 sec   => banned for 1 minute
   12  times in 5 min    => banned for 10 minutes
   40  times in 1 hour   => banned for 3 hours
  100 times in 8 hours => banned for 1 day

#498164#8
Date:
2008-09-08 00:52:27 UTC
From:
To:
PS sorry for double post -- I managed to screw up email address.. please
use this one to reply

Progressive banning time is indeed a nice feature to request and I think
it was requested before. I will just forward this wishlist upstream to
make sure all parties are aware ;-)

#498164#13
Date:
2011-04-01 13:01:30 UTC
From:
To:
Please see
http://whyscream.net/wiki/index.php/Fail2ban_monitoring_Fail2ban

This shows how to implement a two-level blocking scheme, by having
fail2ban parse its *own* logfile.

So, when someone attacks several times, they will be banned
several times. And then fail2ban reacts to its own log,
using a rule specifying a much longer ban.

This also have the advantage of catching
cases where someone tries to break in through several different
services.

Helge Hafting

#498164#18
Date:
2011-04-02 16:41:04 UTC
From:
To:
Thank you Helge for the reminder,

probably I will just include such a filter/jail in the next upload
to close this bugreport

cheers
-- 
=------------------------------------------------------------------=
Keep in touch                                     www.onerussian.com
Yaroslav Halchenko                 www.ohloh.net/accounts/yarikoptic

#498164#23
Date:
2017-01-25 06:46:57 UTC
From:
To:
Dear Customer,

Your item has arrived at the USPS Post Office at January 21, but the courier was unable to deliver parcel to you.

Please review delivery label in attachment!

Your help is greatly appreciated,
Peter Graham,
USPS Chief Delivery Manager.

#498164#24
Date:
2017-02-04 20:02:27 UTC
From:
To:
Dear Customer,

We can not deliver your parcel arrived at February 03.

Review the document that is attached to this e-mail!

All the best,
Nicholas Farrell,
UPS Office Agent.

#498164#29
Date:
2018-01-23 03:05:15 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
fail2ban, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 498164@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Yaroslav Halchenko <debian@onerussian.com> (supplier of updated fail2ban package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 22 Jan 2018 10:38:19 -0500
Source: fail2ban
Binary: fail2ban
Architecture: source all
Version: 0.10.2-1
Distribution: unstable
Urgency: medium
Maintainer: Yaroslav Halchenko <debian@onerussian.com>
Changed-By: Yaroslav Halchenko <debian@onerussian.com>
Description:
 fail2ban   - ban hosts that cause multiple authentication errors
Closes: 470417 498164 847728 878038 881648
Changes:
 fail2ban (0.10.2-1) unstable; urgency=medium
 .
   [ Yaroslav Halchenko ]
   * New major upstream release (thanks to Ervin Hegedüs for help updating
     packaging)
     - Major performance improvements, especially in tests battery
       execution, and shutdown (Closes: #878038)
     - Incremental increase of bantime (Closes: #498164)
     - IPv6 support (Closes: #881648, #470417)
     - Some filters refactored/deprecated, e.g. to take advantage of new
       filter option mode
       - sshd-aggressive and sshd-ddos absorbed into sshd filter
         (modes: normal, ddos, extra, or aggressive)
       - postfix-rbl and postfix-sasl absorbed into postfix
         (modes: more, normal, auth, rbl, ddos, extra, or aggressive)
     - New actions: abuseipd, nginx-block-map
     - New filters: phpmyadmin-syslog, zoneminder
   * A number of new patches added to address failing tests from
https://github.com/fail2ban/fail2ban/pull/2025
   * debian/control
     - Boosted policy to 4.1.3
     - sqlite3 is now needed for some tests, thus added to build-depends
       and suggests
   * debian/README.Debian
     - Instructions on how to establish correct startup/shutdown sequence
       in systemd for shorewall (Closes: #847728). Thanks Ben Coleman for the
       final recipe
 .
   [ Viktor Szépe ]
   * Install provided config for monit under /etc/monit/conf-available
     (instead of /etc/monit/monitrc.d, location changed after monit 1:5.15-2)
Checksums-Sha1:
 7abc12df0f8940297893115c79a1e6cea4ba204f 1897 fail2ban_0.10.2-1.dsc
 e0502d6d1b9aa6416d49ab977dbe3b14cf803c4e 474739 fail2ban_0.10.2.orig.tar.gz
 9041b020e11b7940f68aba6bf7459716eb520620 28920 fail2ban_0.10.2-1.debian.tar.xz
 927f8588fa22482d060c05e96b2a4f610e657846 384024 fail2ban_0.10.2-1_all.deb
 4c612507b7030ff6cc4ab2af2b570b1742b95915 6045 fail2ban_0.10.2-1_amd64.buildinfo
Checksums-Sha256:
 fcd49c3eff53c0b9ff200675522de231ebba172fe44b2efb5aea7bc85b2bba7b 1897 fail2ban_0.10.2-1.dsc
 22744cb9f2dbc50ba50873b14dbfc9b4c078c170f4d29b2600faf3da99b4038d 474739 fail2ban_0.10.2.orig.tar.gz
 7e976c5e052ff482ad571f1f3f4c6d4d0a2e9309e09e59d5ca273158e7e69908 28920 fail2ban_0.10.2-1.debian.tar.xz
 9245f91ef6c03fdf4d026abda93475a94ec61505a62b9554684507d3c1f62c80 384024 fail2ban_0.10.2-1_all.deb
 ffa5a737972350339d3b95801bdbd492627f7c5ae7a8143f732baa3102ec8385 6045 fail2ban_0.10.2-1_amd64.buildinfo
Files:
 bde538ca15b55a19ce11d5366a29ac39 1897 net optional fail2ban_0.10.2-1.dsc
 298a50cbc6298b8aef6a6bf8aae142e6 474739 net optional fail2ban_0.10.2.orig.tar.gz
 20de852436c07475da073e02316625f2 28920 net optional fail2ban_0.10.2-1.debian.tar.xz
 431faabc96c0b1170d026e4b942bd0f6 384024 net optional fail2ban_0.10.2-1_all.deb
 13c951ad840130cbc8b7d54621057c1f 6045 net optional fail2ban_0.10.2-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEExbkF8OjZ/ZZo/zZvot4jUGLaM/oFAlpmoLsACgkQot4jUGLa
M/rBIQ/9HZLQRQHUhWnf9e3uHMje5wvuCMZh2trDBCasHIfF/79IMO6w2JMpCOlM
11swPXkbX3HedFyCJXOt41543/C1vqAWfzk2nUMnz/k3/26M/n0mohJM9CzGmGqT
mYUGpZq9B8ascQirHFJqq3OOU1TunksCqx9uENIGgMuhzKwcMu0ANY6llOn6wwNu
vDRRRfeEMdZrXnyaRzpKdRSuE9Np9o22/vj0L1nGDFWa2cZ3wOtMxmkSM0e89tYi
B5eOdWnLxCyHFj2tSGy7TBmIo61rQCeHfwhGLHjHmXuZc7P3EfQdsSN9bw/g/s1k
9Zs07oIgQ/gqqxReccuzMubAFvA7EOOQCmzHbCsKtyNCwUqp1OFj3oIN9WBr5UWv
/BgJyBmzOwCTjQvgzVSBRF6NDyhEYUeiut/q9nbSvbEgH4BL3XHEVdSRmqNiuS0U
ZaXLnYHWFi5th1HkIO15uYagbbenQLK0Sm8RsYBdnqai+vGkahnJ+DXdjOc6/erw
Mi/04iWcesw3wsT4jBNhAjYAxHtnzRbH09+1z36HUWkeWbF5n9oT3fULKXMXoQHe
c+fK6UgoG9U/P8h0joaWL7b0D0ybfQRO9XPdAu1NtHYjTxNb9Ewn8AECJgylsD4P
lGb8YCfIEYrBHcoz1eaPzscHz4sS2hWVlqj3269MMP88s9NRsLM=
=fHUc
-----END PGP SIGNATURE-----

#498164#38
Date:
2018-01-24 15:05:51 UTC
From:
To:
tags 498164 + fixed-upstream
reopen 498164
thanks

oops, my bad . As Serge reminded, this will be provided in 0.11 release.
So the issue is pending and fixed upstream