Fail2ban Connectivity Issues

There is a security feature called fail2ban deployed on the CS machines which monitors login failures. If there are\(N\) login failures from a particular IP address, then that IP is banned from logging in for the next 24 hours.\(N\) is a relatively small value like 3.

The really irritating aspect of the operation of fail2ban is that it fails silently and the login attempt just hangs without any explanation. This can be extremely frustrating.

The scenarios where fail2ban is triggered include:

  • You are confused about your password and try too many incorrect passwords.

  • Since the ban is by IP address, it could be triggered by someone sharing your IP address. So for example, if you are sharing your internet connection with another CS student and your housemate's login attempts fail, then your login could get banned.

  • I once had a flaky key on my keyboard and was unknowingly typing my password incorrectly.

The fixes I know of:

  1. Wait 24 hours (very frustrating).

  2. Try to use a different IP address:

  3. Use the campus VPN to connect.

SysAdmin Email from Mar 3, 2021.