Intelligent installer (recommended)
One command, paste it into your terminal (PuTTY: right-click pastes):
curl -sS https://reports.provider.tools/api/v1/abuse/fail2ban-install | sudo bash
The installer script:
- installs fail2ban automatically if it is missing (apt/dnf/yum/apk)
- backs up existing configs with timestamps before touching them
- adds the sshd, postfix-sasl and dovecot jails only if they are not configured yet (idempotent)
- sets up the BLOCK consumer - reported attackers are blocked on this server too
- restarts fail2ban and verifies the connection to the network
On the Reporting page you get the same command with a one-click copy button and a "Report only" toggle that switches the command to reporting without blocking.
The block consumer
The installer sets up a dedicated jail provider-tools-block that automatically bans all IPs reported by the community:
- Sync: the current list is pulled every 5 minutes via cron.
- Whitelist: add your own IPs (office, VPN, monitoring) to
/etc/provider-tools/whitelist.txt- they are never banned. - Auto-unban: IPs that are delisted are unbanned automatically.
- Per-service filter: block only attacks against one service with
&block_service=imapin the install command.
Verify:
fail2ban-client status provider-tools-block
Reporting only (no blocking)
If you only want to contribute reports without blocking anything yourself:
curl -sS https://reports.provider.tools/api/v1/abuse/fail2ban-install?block=0 | sudo bash
or use the "Report only" toggle on the Reporting page - it switches the copyable command to &block=0.
Report tokens (optional)
With a free account you can create one report token per server in the "Your Report Tokens" section on the Reporting page (label, e.g. mail-01):
- The one-paste command, action file and jail examples then include your token automatically.
- You see per-server statistics: total reports, last 7 days, currently listed from your reports.
- Tokens build reporter reputation - trusted reporters weigh more.
Without a token, reports are anonymous - they count exactly the same for listing.
Dry run & verification
Dry run (shows what would happen without changing anything):
curl -sS https://reports.provider.tools/api/v1/abuse/fail2ban-install | DRY_RUN=1 sudo bash
After installation, check that reporting works:
grep -r "provider-tools" /etc/fail2ban/action.d/ | head -5
fail2ban-client status provider-tools-block
dig 4.3.2.1.ssh.attacks.provider.tools # check an IP against the ssh zone
Jail examples (manual setup): https://reports.provider.tools/api/v1/abuse/fail2ban-config?format=jails
CrowdSec instead of fail2ban?
You can report attacks from CrowdSec via its built-in HTTP plugin - see the article CrowdSec Integration in the DNSBL category. For blocking reported attackers, combine it with the fail2ban block consumer or the firewall export - CrowdSec alone only reports.
Related articles
Attack Defense - What it is & how it works
The product explained from zero: report attacks from your servers to a global list - and automatically block reported attackers on your own systems. Free, anonymous, GDPR compliant.
ReadIn your firewall: block reported attackers
Block the Attack Defense list directly on routers and border firewalls without fail2ban - iptables, nftables, ufw, pf (BSD) and Windows Firewall, synced every 5 minutes.
ReadCheck IPs: Live Check & DNS
Check whether an IP is listed: web Live Check or dig against the per-service check zones - with return codes, TXT details and the HTTP export.
Read