Labthrift Labthrift What to buy. What to skip. Why.

Written 26 Aug 2026. This is a how-to, not a product card.

Slow down password guesses on SSH

After the firewall is on and key login is boring, you can let the computer briefly refuse an address that keeps guessing the password. Skip this on day one. Don't forward port 22.

SSH belongs on the house network. That is keep the computer on the house network. Don't forward port 22. On a house-only computer, this is optional polish, not a substitute for keeping SSH inside the house. It still helps if someone later opens the router by mistake, or if a phone on the house Wi-Fi keeps hammering a wrong password.

Skip until ufw works

If the simple firewall is not on yet, stop. Allow OpenSSH, then turn on ufw first. Prefer logging in with a key, then turning off password login once the key works, before this polish. If password SSH is still the only login and it is flaky, stop.

What this changes

fail2ban is software that watches the login log and briefly refuses an address that keeps guessing wrong. It reads the login log. After enough wrong guesses from one address, that address cannot try SSH for a short while. Your laptop key login still works. This is not a new firewall appliance. This is not a reason to open port 22 on the router.

Install

From your normal computer, SSH from the couch. Then update the package list:

sudo apt update

Install fail2ban:

sudo apt install fail2ban

On a Debian or Ubuntu computer from what OS to put on the computer, the stock sshd jail is enough for this note.

Turn it on and check

Turn it on so it starts now and after a reboot:

sudo systemctl enable --now fail2ban

Check the SSH jail:

sudo fail2ban-client status sshd

You should see the sshd jail active. If sshd is not listed yet, ask for the whole status:

sudo fail2ban-client status

Wait a minute and check again. Don't paste a long jail.local essay. Stock defaults are fine for this computer.

If you ban yourself

Use another device on the house network, or a screen and keyboard on the computer. Unban that address:

sudo fail2ban-client set sshd unbanip THAT-ADDRESS

Swap THAT-ADDRESS for the number of the laptop or phone that got locked out. SSH stays inside the house, as explained in keep the computer on the house network. Don't solve this by forwarding port 22.

What next

If weekly apt is boring, let the computer apply weekly fixes without you. The honest weekly look is still keep the computer updated. The boundary is still keep the computer on the house network. Skip a Protectli. Skip opening SSH to the internet.

Skip

Sources

fail2ban: documentation. Debian: fail2ban-client. Debian: fail2ban jail.conf. Official pages only. For the firewall, see turn on a simple firewall without locking yourself out. For turning off password login, see turn off password login once the key works. For the house-network boundary, see keep the computer on the house network. For the login, see SSH from the couch.

Also on this topic

Turn on a simple firewall without locking yourself outAfter SSH from the couch works, allow OpenSSH, then turn on ufw. The computer stays reachable. Surprise inbound ports don't. Turn off password login once the key worksAfter the laptop key login is boring, tell SSH to stop accepting the password. The key is how you get in. A keyboard on the computer is the backup now. Keep the computer on the house networkSSH and Pi-hole belong on the house network. Skip this if you never opened the router settings. Don't forward port 22. See if anyone guessed the passwordBefore you buy a camera or extra login software, peek at failed logins with lastb. Let the computer apply weekly fixes without youAfter the weekly two-command habit is boring, you can let the computer apply those same fixes by itself. Skip this until that habit is boring. Don't let it reboot on its own.