Central fail2ban console for personal serversFreeSelf-hosted

All your fail2ban servers,
seen and blocked from one screen.

SSem SecuMon is a free central fail2ban console for individuals who run their own VPS or home servers. Put a small agent on each server to see who is blocked right now and how many times they have offended, all on one screen, and enforce ban · unban · range block · country blocking with signed commands.

Linux servers + fail2ban · nftables · The agent opens no inbound ports · You install the console on your own server

secumon DashboardBan listTargetsEnforcementCountry blocking admin · ADMIN
Current bans128Across 3 servers
New today3712 more than yesterday
Repeat offenders193+ cumulative bans
Auto-blocked6Last 24 hours
Ban trend · 24 hoursweb-01vpn-gw
Servers3 agents
  • web-0112s ago
  • vpn-gw8s ago
  • home-nas21s ago
IPs blocked right now128
IPServersjailOffense levelCountryTime left
203.0.113.45web-01 · vpn-gwsshdLevel 4 · 8hXA5h 12m
198.51.100.7vpn-gwsshdLevel 2 · 2hXB1h 40m
203.0.113.201home-nassshdLevel 3 · 4hXC3h 5m
192.0.2.88web-01apache-authLevel 1 · 1hXD24m

Server names, IPs and countries in the sample screens are made up (the IPs come from ranges reserved for documentation; the country codes XA–XD are placeholders).

Even personal servers get knocked on every day

A server open to the internet gets thousands of login attempts a day. fail2ban stops them, but as soon as you run more than one server, things start to slip out of view.

You have to check each server separately

To see who is blocked, you have to SSH into each server and run fail2ban-client. You also can’t see the same IP knocking on several servers.

Exponential bans eventually expire

Repeat offenders are blocked for longer and longer, but in time they are let back in. Someone who comes back a third time isn’t making a mistake — they keep knocking.

Range blocks are easy to get wrong

Adding and updating thousands of IP ranges in every server’s firewall takes a lot of work. One wrong entry can cut off your own access.

At a glance

Watch, block and block broadly — all from one console. Every screen below shows made-up sample data.

Follow one IP all the way

Click an IP in the ban list to see, in one place, the servers that banned it, its ban history, its current level and the expected length of its next ban.

  • Shows every server where the same IP is banned
  • Countries come from a built-in lookup table — no external API quota used
  • Unban · range block · AbuseIPDB report, right there
203.0.113.45XA4 offenses
Banned on
web-01 · vpn-gw
Current level
Level 4 · 8h
Next ban (est.)
16 hours
Reputation score
100 / 100

Ban history — 1h → 2h → 4h → 8h

UnbanRange blockReport to AbuseIPDB

Broad blocks get a second check

Range blocking is the most dangerous feature, so several layers of safeguards guard against mistakes. You must re-type the range before the block runs, and by default it lifts itself after 30 days.

  • Ranges wider than IPv4 /16 · IPv6 /48 are rejected
  • Private networks · loopback · ranges you specify can’t be blocked
  • Several ranges × several servers at once
Range block
Range
203.0.113.0/24
Addresses
256
Servers
web-01 · vpn-gw
Duration
Lifts automatically after 30 days

Protected ranges (private networks · VPN · your servers) can’t be blocked.

CancelBlock

Block whole countries, too

Adds the IP ranges of the countries you choose, out of 233, to your servers’ firewalls. As soon as you turn one on, the list is fetched and applied to every server within 30 seconds.

  • Nothing is re-sent to servers when nothing has changed
  • Fixed rule order, so replies on established connections and DNS are never blocked
  • Shows the number of ranges before you turn it on
Country blocking 2 countries · 4,600 ranges
  • XACountry A3,120 ranges
  • XBCountry B1,480 ranges
  • XCCountry C9,860 ranges
  • XDCountry D640 ranges

Authoritative DNS (53) is always allowed. If you run inbound mail or a VPN, check the guide first.

What can it do?

Watching, blocking, and blocking on its own — just as much as a handful of personal servers needs.

Unified dashboard

See current bans · cumulative bans · repeat offenders · trends for every server on one screen. You can also narrow it down to a single server.

Repeat-offense levels

Reads fail2ban’s exponential ban times (1 · 2 · 4 · 8… ×) to show which level an IP is at and how long its next ban will be.

Ban · unban

Send commands straight from the screen. The agent on the server runs them only after verifying the signature, and every result is kept in the command history.

Range block

Width limits · protected ranges · confirmation input · automatic expiry (30 days by default) guard against mistakes. Ranges already covered by a wider block are skipped.

Automatic blocking of repeat offenders

IPs banned 3 or more times are blocked on every server for 30 days. Single IPs only, at most 20 per run, and every action is logged and notified.

Public blocklists

Fetches Spamhaus DROP · FireHOL level1 once a day and applies them to every server. Entries that overlap your own ranges are filtered out first.

Country blocking

Adds the ranges of the countries you choose to a dedicated list in your servers’ firewalls. Turning it off empties only that list — other blocks stay as they are.

AbuseIPDB · Telegram

Report only banned IPs to AbuseIPDB and look up their reputation. Automatic blocks and list changes are announced on Telegram. Keys stay on the console server only.

Audit log · two-factor authentication

Every enforcement action, report and login is recorded. Three roles — viewer · operator · administrator — plus TOTP two-factor authentication.

How does it work?

The console never pushes commands to your servers. The agent on each server connects out to the console first, uploads its status, picks up signed commands, verifies them itself and only then runs them.

  1. Report status Every 30 seconds the agent reads the fail2ban and firewall status, signs it with its own key and sends it to the console.
  2. Collect in one place The console gathers the status of every server into one database. Every server shows up on the same screen.
  3. Commands go to a queue When you click ban or block, the console only signs the command and puts it in a queue — it never connects to the server.
  4. Verify, then run The agent runs only commands that pass every check: signature · target server · expiry (60 seconds) · replay.
  5. root for one wrapper only The agent does not run as root. Privileged work goes through a single root wrapper that accepts only allowed actions.

The firewall decides in this order

SecuMon uses its own nftables table that never mixes with fail2ban’s rules. Blocks are split into three layers so you can always tell “why it was blocked”, and updating one layer leaves the others untouched.

  1. 1Replies on established connectionsAllow
  2. 2DNS (53)Allow
  3. 3Manual · automatic blocksBlock · lifted on expiry
  4. 4Public blocklistsBlock
  5. 5CountryBlock

Security principles

Built so that a tool you add to protect your servers doesn’t become a new hole.

  • Servers open no inbound ports. The agent always connects out to the console first.
  • Every command is signed with Ed25519. It expires after 60 seconds, runs only once, and runs only on the server it names.
  • Only five allowed actions. Status check · ban · unban · range block · unblock — run as argument arrays only, never through a shell.
  • Your own access paths are never blocked. The console refuses to block private networks · loopback · ranges you specify, and the wrapper on the server checks every command once more.
  • Secrets go in as files only. API keys · the Telegram token · signing keys are supplied as files on the console server, and passwords are hashed with PBKDF2.
  • Logins are protected. TOTP two-factor authentication, a 15-minute lockout after 5 failures, and a CSRF token check on every request that changes state.

Requirements

Servers to protect
Linux (systemd) + fail2ban · nftables · sqlite3. amd64 · arm64. Tested on Ubuntu 22.04 · CentOS 8.
Console server
One. JDK 21 · Tomcat 11 · PostgreSQL 17. Easiest to run with Docker.
Network
Your servers only need to reach the console address over HTTPS. We recommend keeping the console behind a VPN or an internal network.
Clock
Sync every server’s clock with NTP. Signatures more than 60 seconds off are rejected.
Interface language
The console screens and log messages are currently available in Korean only. This introduction and the guide can be read in 10 languages.
Price
Free. Built for personal servers.

Coming soonInstaller downloads are still being prepared.

In the meantime, check the requirements and installation steps in the free guide.

Read the free guide

Get started with the free guide

From prerequisites to your first block, step by step, starting with a single personal server.
It also covers what you must know before turning on country blocking.

Read the free guide

Questions? halo@levelupsoft.com