Alternatives to Fail2ban

Log-watching daemon that bans addresses after repeated authentication failures. The listings below can replace it for an important use case. Each note says what changes if you switch.

The original

Replacements

Listings that take over the same core job as Fail2ban.

  • CrowdSec

    Detect suspicious behavior in server logs and web traffic.

    CrowdSec detects suspicious behavior in logs with configurable scenarios and community intelligence, runs on Windows as well, and needs a separate enforcement integration to block traffic.

  • OSSEC

    An open-source host-based intrusion detection system with log analysis, file integrity monitoring and active response.

    OSSEC is a self-hosted host intrusion detection system that combines log analysis with file integrity monitoring and active response, giving broader coverage with more configuration to learn.

Similar software

Related functionality, not a direct replacement.