Proving the Ban Lands: fail2ban Config You Can Actually Verify
Ours was installed, configured, and enabled — and dead for 95 days, because “enabled” describes what systemd intends at boot, not what survived it, and an empty firewall chain looks identical to a working one. The four-command drill that proves a ban reaches the kernel, why “grep for your f2b chain” turns out not to be a readiness test at all, the five clocks to read together, and the two honest side effects of testing on a live box.
Read Article