# Fail2ban for mqtts + is fail2ban useful for servers that use only ssh keys to log in?

**URL:** <https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789>\
**Category:** General\
**Created:** [26 January 2021 15:48 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789 "2021-01-26T15:48:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![saeed1](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@saeed1](https://discourse.nodered.org/u/saeed1)\
**Post date:** [26 January 2021 15:48 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/1 "2021-01-26T15:48:07Z")

</div>

Hello Guys,

I have two questions

1. I am trying to set fail2ban for mqtts (port 8883). On my server port 8883 is open for the world. The only, who have credentials for mosquitto, can connect and send data to my server. Now i have set the fail2ban for mqtts, but i dont know i can i test this, is it working or not!  
I have another client, i wanted to send the data via this client to my server with wrong credentials and wanted to see if my server can block the IP of this client. But the problem is untill i dont provide the correct credential to my mqtts node (clien side) it cant dare to connect with server. Could you please tell me, how can i test this.

2. Is fail2ban useful for the servers that use only permit ssh keys authentication ??? I have verified that fail2ban works fine for password base authentication, but my server have ssh key based authentiaction. Is it make sense to install this fail2ban package, if i am using ssh keys already?

---

<div class="post-metadata">

**Author:** ![edje11](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/edje11/32/572_2.png) [@edje11](https://discourse.nodered.org/u/edje11)\
**Post date:** [26 January 2021 16:04 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/2 "2021-01-26T16:04:14Z")

</div>

Hi,  
i don't think you get much reply's here because this is the Nodered forum and probably there are not much fail2ban users here.  
You can better ask on a fail2ban forum or google for the solution.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 January 2021 20:32 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/3 "2021-01-26T20:32:22Z")

</div>

1. Not really clear what you are asking there. You need someone on a different IP address to attempt multiple unsuccessful logins within the set timeperiod defined in fail2ban.

2. Yes, it is useful - if you configure it. All it does is look for patterns in logfiles and if it finds one, adds the source address to the firewall to prevent access. Usually prevention is for a period of time. So any error you can find in a log file - in theory at least - could be used in fail2ban.

Of course, fail2ban is only 1 part of a defence in depth strategy that you should be using to defend your servers. Think about 2FA, whitelisting IP addresses, geobanning, changing incoming IP port numbers from their defaults, timelocks, etc.

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [27 January 2021 03:43 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/4 "2021-01-27T03:43:35Z")

</div>

Yes it is useful (and mandatory almost) if you are planning on opening up mqtts to the whole internet

Once you have it setup and configured (for say 3 failed attempts) (and you will need to make sure your broker for mqtts either outputs to a logfile that fail2ban is monitoring - or change the config on failto2ban to look at the mosquitto logs

Then from a remote location try and force an mqtts connection from your clients with incorrect credentials - you can use a number of free tools to do this - or commandline tools depending on what you are comfortable with

Craig

---

<div class="post-metadata">

**Author:** ![saeed1](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@saeed1](https://discourse.nodered.org/u/saeed1)\
**Post date:** [27 January 2021 08:51 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/5 "2021-01-27T08:51:53Z")

</div>

[DEFAULT]

bantime = 600

findtime = 600

banaction = ufw

maxretry = 3

[mosquitto]  
enabled = true  
port = 8883  
logpath = /var/log/auth.log

Still not successful ! where i am doing the mistake? Please @craigcurtin @TotallyInformation

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [27 January 2021 20:58 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/6 "2021-01-27T20:58:10Z")

</div>

Do Mosquitto login errors actually appear in that log?

What is fail2ban checking? Is it checking for the right text pattern?

Have you tried asking on a fail2ban forum, or an MQTT forum or on StackOverflow?

---

<div class="post-metadata">

**Author:** ![craigcurtin](https://avatars.discourse-cdn.com/v4/letter/c/94ad74/32.png) [@craigcurtin](https://discourse.nodered.org/u/craigcurtin)\
**Post date:** [27 January 2021 22:55 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/7 "2021-01-27T22:55:55Z")

</div>

> <https://unix.stackexchange.com/questions/489370/mosquitto-bruteforce-fail2ban-failregex>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [28 March 2021 22:56 UTC](https://discourse.nodered.org/t/fail2ban-for-mqtts-is-fail2ban-useful-for-servers-that-use-only-ssh-keys-to-log-in/39789/8 "2021-03-28T22:56:12Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
