When Fail2ban Starts Struggling in Production
About six months ago, I took over a cluster of 20 Ubuntu VPS instances running API gateways and Nginx reverse proxies. At the time, the system relied on Fail2ban to block scanners. Issues arose immediately: botnets rotated through tens of thousands of clean IPs. Each IP only knocked with 1–2 requests before disappearing. Fail2ban was completely helpless because it never hit the threshold (maxretry) to trigger a ban.
Moreover, Fail2ban operates locally on each machine. An IP attacking Server A would get banned, but two seconds later, it was freely scanning Server B. On top of that, Fail2ban’s Python regex worker consistently consumed 35–40% CPU whenever Nginx logs crossed 15GB/day. I decided to replace it entirely with CrowdSec. Since then, it has become the very first security package I install on every new server cluster.
How Does CrowdSec Work Differently?
CrowdSec solves detection and remediation through a clean, decoupled 3-part architecture:
- CrowdSec Security Engine (Agent): Written in Golang, using under 60MB of RAM. The engine only parses logs (Nginx, SSH, Syslog, Docker…) and matches them against attack detection scenarios defined in YAML.
- Remediation Components (Bouncers): The enforcement arm. While the Engine detects and decides to block, Bouncers push rules to
nftables,iptables, Nginx Lua, or present CAPTCHAs to users. - Community Threat Intelligence (CTI): The most valuable feature. When your server detects an IP scanning for WordPress vulnerabilities, it sends an anonymous signal to the central analysis engine. If thousands of other servers report the same behavior, that IP is instantly added to the global Blocklist. Your server automatically blocks it before the attacker can even send their first request.
Hands-On Guide: Installing and Configuring CrowdSec on Ubuntu
Here are the step-by-step instructions for deploying CrowdSec on Ubuntu 22.04 / 24.04 LTS.
Step 1: Install the CrowdSec Security Engine
Add the official CrowdSec repository to ensure you always receive the latest updates:
# Download the APT repository setup script
curl -s https://packagecloud.io/install/repositories/crowdsec/crowdsec/script.deb.sh | sudo bash
# Install the CrowdSec engine
sudo apt install -y crowdsec
# Check service status
sudo systemctl status crowdsec
Once started, CrowdSec automatically detects system logs in /var/log/auth.log and pre-activates default parsers for Linux and SSH.
Step 2: Install the Firewall Bouncer to Enforce IP Bans
The Engine only analyzes logs and does not block traffic by itself. You need to install a Bouncer at the firewall layer (supporting both iptables and nftables):
# Install the firewall bouncer
sudo apt install -y crowdsec-firewall-bouncer-iptables
# Verify that the bouncer is registered with the Local API (LAPI)
sudo cscli bouncers list
If installed properly, the following table will be displayed:
------------------------------------------------------------------------------------------------------------------------
NAME IP ADDRESS VALID LAST API PULL TYPE VERSION
------------------------------------------------------------------------------------------------------------------------
firewall_bouncer-1696238491 127.0.0.1 ✔ 2024-03-20T10:15:30Z crowdsec-firewall-bouncer v0.0.28
------------------------------------------------------------------------------------------------------------------------
Step 3: Configure Protection for Nginx Web Server
For web servers, install the Nginx collection to detect SQLi, Path Traversal, bot scans, and common CVEs:
# Install the Nginx collection from the CrowdSec Hub
sudo cscli collections install crowdsecurity/nginx
# Open the log acquisition configuration file
sudo nano /etc/crowdsec/acquis.yaml
Verify and ensure CrowdSec is reading the correct access log path:
filenames:
- /var/log/nginx/*.log
labels:
type: nginx
---
Restart the engine to apply the new rules:
sudo systemctl restart crowdsec
Step 4: Connect to CrowdSec Console for Centralized Management
Managing two or more servers calls for a unified overview dashboard. Take advantage of the free CrowdSec Console web interface:
# Sign up at app.crowdsec.net, obtain your enroll key, and run:
sudo cscli console enroll <YOUR_ENROLL_KEY>
# Reload the service
sudo systemctl restart crowdsec
Step 5: Testing and Common Operational Commands
You can inspect the blocklist or manually ban IPs using the cscli command:
# View recent attack alerts
sudo cscli alerts list
# Check all active ban decisions
sudo cscli decisions list
# Manually ban a suspicious IP for 4 hours
sudo cscli decisions add --ip 198.51.100.42 --duration 4h --reason "manual block malicious bot"
# Unban an IP immediately (e.g. accidentally banned dev/client)
sudo cscli decisions delete --ip 198.51.100.42
# View parsed log statistics and rule match metrics
sudo cscli metrics
Conclusion
Migrating from Fail2ban to CrowdSec shifts your defenses from reactive to proactive. Instead of waiting for an attacker to fail authentication dozens of times, your server benefits from a community-driven database of millions of malicious IPs. CPU utilization drops significantly, junk log volume decreases, and centralized monitoring via CLI and Web Console saves operational teams hours of debugging every week.

