<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<oembed><type>rich</type><version>1.0</version><provider_name>phorkie</provider_name><provider_url>https://p.cweiske.de/</provider_url><title>fail2ban: immediately block ssh connects with invalid user</title><author_name>Christian Weiske</author_name><cache_age>86400</cache_age><width>900</width><height>900</height><html>&lt;!-- embedding all files of https://p.cweiske.de/598 --&gt;
&lt;link rel="stylesheet" href="https://p.cweiske.de/css/embed.css"/&gt;
&lt;div class="phork" id="598"&gt;
    &lt;div class="phork-file"&gt;
 &lt;div class="phork-content"&gt;
  
&lt;div class="document"&gt;


&lt;p&gt;This works with fail2ban 0.9.6-2 on Debian 9.&lt;/p&gt;
&lt;/div&gt;

 &lt;/div&gt;
 &lt;div class="phork-meta"&gt;
  &lt;a href="https://p.cweiske.de/598/rev-raw/f29444715f5d1704bda3cf77e58cfb44f49ea26c/README.rst" style="float: right"&gt;view raw source&lt;/a&gt;
  &lt;a href="https://p.cweiske.de/598#README.rst"&gt;README.rst&lt;/a&gt;
 &lt;/div&gt;
&lt;/div&gt;
    &lt;div class="phork-file"&gt;
 &lt;div class="phork-content"&gt;
  &lt;style type="text/css"&gt;/**
 * GeSHi (C) 2004 - 2007 Nigel McNie, 2007 - 2014 Benny Baumann
 * (http://qbnz.com/highlighter/ and http://geshi.org/)
 */
.ini .de1, .ini .de2 {font: normal normal 1em/1.2em monospace; margin:0; padding:0; background:none; vertical-align:top;}
.ini  {font-family:monospace;}
.ini .imp {font-weight: bold; color: red;}
.ini li, .ini .li1 {color: #DDD;}
.ini .ln {width:1px;text-align:right;margin:0;padding:0 2px;vertical-align:top;}
.ini .co0 {color: #666666; font-style: italic;}
.ini .sy0 {color: #000066; font-weight:bold;}
.ini .st0 {color: #933;}
.ini .re0 {color: #000066; font-weight:bold;}
.ini .re1 {color: #000099;}
.ini .re2 {color: #660066;}
.ini span.xtra { display:block; }
&lt;/style&gt;&lt;div class="code"&gt;&lt;table class="ini"&gt;&lt;tbody&gt;&lt;tr class="li1"&gt;&lt;td class="ln"&gt;&lt;pre class="de1"&gt;1
2
3
4
5
6
7
8
9
10
11
12
&lt;/pre&gt;&lt;/td&gt;&lt;td class="de1"&gt;&lt;pre class="de1"&gt;&lt;span class="re0"&gt;&lt;span class="br0"&gt;&amp;#91;&lt;/span&gt;INCLUDES&lt;span class="br0"&gt;&amp;#93;&lt;/span&gt;&lt;/span&gt;
&lt;span class="re1"&gt;before&lt;/span&gt; &lt;span class="sy0"&gt;=&lt;/span&gt;&lt;span class="re2"&gt; common.conf&lt;/span&gt;
&amp;#160;
&lt;span class="re0"&gt;&lt;span class="br0"&gt;&amp;#91;&lt;/span&gt;Definition&lt;span class="br0"&gt;&amp;#93;&lt;/span&gt;&lt;/span&gt;
&lt;span class="re1"&gt;_daemon&lt;/span&gt; &lt;span class="sy0"&gt;=&lt;/span&gt;&lt;span class="re2"&gt; sshd&lt;/span&gt;
&amp;#160;
&lt;span class="re1"&gt;failregex&lt;/span&gt; &lt;span class="sy0"&gt;=&lt;/span&gt;&lt;span class="re2"&gt; ^%&lt;span class="br0"&gt;&amp;#40;&lt;/span&gt;__prefix_line&lt;span class="br0"&gt;&amp;#41;&lt;/span&gt;s&lt;span class="re0"&gt;&lt;span class="br0"&gt;&amp;#91;&lt;/span&gt;iI&lt;span class="br0"&gt;&amp;#93;&lt;/span&gt;&lt;/span&gt;&lt;span class="br0"&gt;&amp;#40;&lt;/span&gt;?:llegal|nvalid&lt;span class="br0"&gt;&amp;#41;&lt;/span&gt; user .*? from &amp;lt;HOST&amp;gt;&lt;span class="br0"&gt;&amp;#40;&lt;/span&gt;?: port \d+&lt;span class="br0"&gt;&amp;#41;&lt;/span&gt;?\s*$&lt;/span&gt;
&lt;span class="re1"&gt;ignoreregex&lt;/span&gt; &lt;span class="sy0"&gt;=&lt;/span&gt; 
&amp;#160;
&lt;span class="re0"&gt;&lt;span class="br0"&gt;&amp;#91;&lt;/span&gt;Init&lt;span class="br0"&gt;&amp;#93;&lt;/span&gt;&lt;/span&gt;
&lt;span class="re1"&gt;journalmatch&lt;/span&gt; &lt;span class="sy0"&gt;=&lt;/span&gt;&lt;span class="re2"&gt; _SYSTEMD_UNIT=sshd.service + _COMM=sshd&lt;/span&gt;
&amp;#160;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
 &lt;/div&gt;
 &lt;div class="phork-meta"&gt;
  &lt;a href="https://p.cweiske.de/598/rev-raw/f29444715f5d1704bda3cf77e58cfb44f49ea26c/filter.d/sshd-invaliduser.conf" style="float: right"&gt;view raw source&lt;/a&gt;
  &lt;a href="https://p.cweiske.de/598#filter.d/sshd-invaliduser.conf"&gt;filter.d/sshd-invaliduser.conf&lt;/a&gt;
 &lt;/div&gt;
&lt;/div&gt;
    &lt;div class="phork-file"&gt;
 &lt;div class="phork-content"&gt;
  &lt;style type="text/css"&gt;&lt;/style&gt;&lt;div class="code"&gt;&lt;table class="local"&gt;&lt;tbody&gt;&lt;tr class="li1"&gt;&lt;td class="ln"&gt;&lt;pre class="de1"&gt;1
2
3
4
5
6
7
&lt;/pre&gt;&lt;/td&gt;&lt;td class="de1"&gt;&lt;pre class="de1"&gt;[sshd-invaliduser]&#13;
enabled = true&#13;
maxretry = 1&#13;
port &amp;#160; &amp;#160;= ssh&#13;
logpath = %(sshd_log)s&#13;
backend = %(sshd_backend)s&#13;
&amp;#160;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
 &lt;/div&gt;
 &lt;div class="phork-meta"&gt;
  &lt;a href="https://p.cweiske.de/598/rev-raw/f29444715f5d1704bda3cf77e58cfb44f49ea26c/jail.local" style="float: right"&gt;view raw source&lt;/a&gt;
  &lt;a href="https://p.cweiske.de/598#jail.local"&gt;jail.local&lt;/a&gt;
 &lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</html></oembed>
