TL;DR Fail2ban
Fail2ban runs on every CloudSonic server alongside CrowdSec, banning IP addresses that show signs of brute force attacks before they can cause damage.
Fail2ban is an intrusion prevention framework that monitors authentication logs and bans IP addresses that repeatedly fail login attempts. It runs on every CloudSonic server and is particularly effective against SSH brute force attacks and WordPress login page attacks. Fail2ban works alongside CrowdSec, AppArmor, and UFW as one of four independent security layers active on every CloudSonic server.
Fail2ban for Intrusion Prevention on CloudSonic
Fail2ban on CloudSonic monitors SSH authentication logs and Nginx access logs for repeated failed login attempts, automatically adding temporary bans to UFW after a configurable number of failures. It is particularly effective against WordPress login page brute force attacks and SSH credential stuffing, catching automated attempts that slip through before CrowdSec's community blocklist catches the source IP. Fail2ban works alongside CrowdSec, AppArmor, and UFW as one of four independent security layers active on every CloudSonic server.
Useful Commands
sudo fail2ban-client status
sudo fail2ban-client status sshd