Angriffsabwehr6 min read6 sections

On your server: fail2ban (reporting & auto-blocking)

One command installs reporting AND automatic blocking of reported attackers on your server - with block consumer, 5-minute sync, whitelist and per-service filtering.

01

Intelligent installer (recommended)

One command, paste it into your terminal (PuTTY: right-click pastes):

curl -sS https://reports.provider.tools/api/v1/abuse/fail2ban-install | sudo bash

The installer script:

  • installs fail2ban automatically if it is missing (apt/dnf/yum/apk)
  • backs up existing configs with timestamps before touching them
  • adds the sshd, postfix-sasl and dovecot jails only if they are not configured yet (idempotent)
  • sets up the BLOCK consumer - reported attackers are blocked on this server too
  • restarts fail2ban and verifies the connection to the network

On the Reporting page you get the same command with a one-click copy button and a "Report only" toggle that switches the command to reporting without blocking.

02

The block consumer

The installer sets up a dedicated jail provider-tools-block that automatically bans all IPs reported by the community:

  • Sync: the current list is pulled every 5 minutes via cron.
  • Whitelist: add your own IPs (office, VPN, monitoring) to /etc/provider-tools/whitelist.txt - they are never banned.
  • Auto-unban: IPs that are delisted are unbanned automatically.
  • Per-service filter: block only attacks against one service with &block_service=imap in the install command.

Verify:

fail2ban-client status provider-tools-block
03

Reporting only (no blocking)

If you only want to contribute reports without blocking anything yourself:

curl -sS https://reports.provider.tools/api/v1/abuse/fail2ban-install?block=0 | sudo bash

or use the "Report only" toggle on the Reporting page - it switches the copyable command to &block=0.

04

Report tokens (optional)

With a free account you can create one report token per server in the "Your Report Tokens" section on the Reporting page (label, e.g. mail-01):

  • The one-paste command, action file and jail examples then include your token automatically.
  • You see per-server statistics: total reports, last 7 days, currently listed from your reports.
  • Tokens build reporter reputation - trusted reporters weigh more.

Without a token, reports are anonymous - they count exactly the same for listing.

05

Dry run & verification

Dry run (shows what would happen without changing anything):

curl -sS https://reports.provider.tools/api/v1/abuse/fail2ban-install | DRY_RUN=1 sudo bash

After installation, check that reporting works:

grep -r "provider-tools" /etc/fail2ban/action.d/ | head -5
fail2ban-client status provider-tools-block
dig 4.3.2.1.ssh.attacks.provider.tools        # check an IP against the ssh zone

Jail examples (manual setup): https://reports.provider.tools/api/v1/abuse/fail2ban-config?format=jails

06

CrowdSec instead of fail2ban?

You can report attacks from CrowdSec via its built-in HTTP plugin - see the article CrowdSec Integration in the DNSBL category. For blocking reported attackers, combine it with the fail2ban block consumer or the firewall export - CrowdSec alone only reports.