How to protect WordPress with Fail2Ban
Using WP Cerber and Fail2Ban together you can reinforce protection at the most effective level. That allows you to protect site from Brute-force and some DDOS attacks at OS level with iptables.
Note: you need root access to your Linux server to setup Fail2Ban.
With WP Cerber security plugin you have three options to use Fail2Ban
- Using HTTP 403 response headers if you want to monitor Apache access log
- Using syslog files to monitor failed login attempts
- Using specified custom log file to monitor failed login attempts
Let’s look at the details.
Monitor Apache access log for HTTP 403 responses
When attempt to login fails WP Cerber provides returning 403 response in the HTTP header. That response will be written in the Apache access log and those records may be monitored by Fail2Ban. That behavior of WP Cerber is enabled by default. The downside to this approach is that Fail2Ban has to parse the entire access.log in order to find those attempts.
Using syslog to monitor failed login attempts
By default, WP Cerber uses LOG_AUTH facility for logging failed attempts to the syslog file. However, you can use your own value for facility. To setup new value you have to define CERBER_LOG_FACILITY constant with integer value. To enable writing to the syslog or custom file (see below) you need to check Write failed login attempts to the file in the Activity section of settings.
Using custom log file to monitor failed login attempts
If you want to write all failed attempts to any custom log file you need to specify a file name with absolute path using constant CERBER_FAIL_LOG. Don’t forget set write permission for Apache proccess on the folder or log file and check Write failed login attempts to the file. If the file does not exist, WP Cerber attempts to create it. If the CERBER_FAIL_LOG is defined, WP Cerber will not write messages to the default syslog.
Last posts from WordPress security blog
- WP Cerber 4.0 01/16/2017
- WordPress 4.7.1 – eight security issues has been fixed 01/11/2017
- WP Cerber has got 20,000 active installs 12/20/2016
- WP Cerber Security 3.0 12/09/2016
- WP Cerber Hooks 12/08/2016