Stop SSH brute force with fail2ban
Install fail2ban from EPEL on AlmaLinux, Rocky Linux or RHEL 9/10 and ban IPs that hammer sshd, with nftables bans and safe unban commands.
- Works on
- EL 9 · EL 10
- Time
- 15 minutes
- Ingredients
- 2 packages
Concrete server tasks on RHEL, AlmaLinux and Rocky Linux. Each recipe lists its package ingredients, the releases it works on, and the date it was last executed end to end in a clean environment.
Install fail2ban from EPEL on AlmaLinux, Rocky Linux or RHEL 9/10 and ban IPs that hammer sshd, with nftables bans and safe unban commands.
Install Valkey from AppStream on AlmaLinux, Rocky Linux or RHEL 9/10, migrate an existing Redis dump, and verify persistence across restarts.
Run the clamd scanning daemon from EPEL on EL 9/10, keep signatures fresh with freshclam, scan web upload directories on a timer, and verify detection with EICAR.
Set up restic from EPEL on EL 9/10 for encrypted, deduplicated backups with a systemd timer, retention policy, integrity checks and a tested restore.
Enable Brotli compression in NGINX on EL 9/10 with prebuilt RPMs - the in-distro EPEL module or GetPageSpeed's current-NGINX build - with measured size savings.