Stop SSH brute force with fail2ban
Install fail2ban from EPEL on AlmaLinux, Rocky Linux or RHEL 9/10 and ban IPs that hammer sshd, with nftables bans and safe unban commands.
- Works on
- EL 9 · EL 10
- Time
- 15 minutes
- Ingredients
- 2 packages
Extra Packages for Enterprise Linux, closer to you
epel.cloud serves the EPEL package repositories through Cloudflare's
edge cache, so dnf fetches metadata and RPMs from a location near your
servers. The cookbook is a small set of Enterprise Linux recipes we actually ran,
with real output, on the dates stamped on them.
[epel]
name=EPEL $releasever via epel.cloud
baseurl=https://epel.cloud/pub/epel/$releasever/Everything/$basearch/
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-$releasever
Every recipe was executed start to finish in a clean Enterprise Linux environment before publishing. The stamp shows when.
Install fail2ban from EPEL on AlmaLinux, Rocky Linux or RHEL 9/10 and ban IPs that hammer sshd, with nftables bans and safe unban commands.
Install Valkey from AppStream on AlmaLinux, Rocky Linux or RHEL 9/10, migrate an existing Redis dump, and verify persistence across restarts.
Run the clamd scanning daemon from EPEL on EL 9/10, keep signatures fresh with freshclam, scan web upload directories on a timer, and verify detection with EICAR.
Set up restic from EPEL on EL 9/10 for encrypted, deduplicated backups with a systemd timer, retention policy, integrity checks and a tested restore.
Enable Brotli compression in NGINX on EL 9/10 with prebuilt RPMs - the in-distro EPEL module or GetPageSpeed's current-NGINX build - with measured size savings.
The mirror namespace is /pub/epel/, the same layout as any
Fedora mirror. EPEL 8, 9 and 10 are served live; EPEL 7 requests redirect to the
Fedora archives where they now live. RPM bytes and GPG signatures are passed
through unchanged from Fedora's own download servers, so gpgcheck=1
keeps working exactly as upstream intends.
There is no signup, no token and no rate limit aimed at package managers.
If you run Enterprise Linux machines far from the US, pointing
dnf here usually shortens metadata refresh and download times.
Setup instructions →