You have to check each server separately
To see who is blocked, you have to SSH into each server and run fail2ban-client. You also can’t see the same IP knocking on several servers.
SSem SecuMon is a free central fail2ban console for individuals who run their own VPS or home servers. Put a small agent on each server to see who is blocked right now and how many times they have offended, all on one screen, and enforce ban · unban · range block · country blocking with signed commands.
| IP | Servers | jail | Offense level | Country | Time left |
|---|---|---|---|---|---|
| 203.0.113.45 | web-01 · vpn-gw | sshd | Level 4 · 8h | XA | 5h 12m |
| 198.51.100.7 | vpn-gw | sshd | Level 2 · 2h | XB | 1h 40m |
| 203.0.113.201 | home-nas | sshd | Level 3 · 4h | XC | 3h 5m |
| 192.0.2.88 | web-01 | apache-auth | Level 1 · 1h | XD | 24m |
Server names, IPs and countries in the sample screens are made up (the IPs come from ranges reserved for documentation; the country codes XA–XD are placeholders).
A server open to the internet gets thousands of login attempts a day. fail2ban stops them, but as soon as you run more than one server, things start to slip out of view.
To see who is blocked, you have to SSH into each server and run fail2ban-client. You also can’t see the same IP knocking on several servers.
Repeat offenders are blocked for longer and longer, but in time they are let back in. Someone who comes back a third time isn’t making a mistake — they keep knocking.
Adding and updating thousands of IP ranges in every server’s firewall takes a lot of work. One wrong entry can cut off your own access.
Watch, block and block broadly — all from one console. Every screen below shows made-up sample data.
Click an IP in the ban list to see, in one place, the servers that banned it, its ban history, its current level and the expected length of its next ban.
Ban history — 1h → 2h → 4h → 8h
Range blocking is the most dangerous feature, so several layers of safeguards guard against mistakes. You must re-type the range before the block runs, and by default it lifts itself after 30 days.
Protected ranges (private networks · VPN · your servers) can’t be blocked.
Adds the IP ranges of the countries you choose, out of 233, to your servers’ firewalls. As soon as you turn one on, the list is fetched and applied to every server within 30 seconds.
Authoritative DNS (53) is always allowed. If you run inbound mail or a VPN, check the guide first.
Watching, blocking, and blocking on its own — just as much as a handful of personal servers needs.
See current bans · cumulative bans · repeat offenders · trends for every server on one screen. You can also narrow it down to a single server.
Reads fail2ban’s exponential ban times (1 · 2 · 4 · 8… ×) to show which level an IP is at and how long its next ban will be.
Send commands straight from the screen. The agent on the server runs them only after verifying the signature, and every result is kept in the command history.
Width limits · protected ranges · confirmation input · automatic expiry (30 days by default) guard against mistakes. Ranges already covered by a wider block are skipped.
IPs banned 3 or more times are blocked on every server for 30 days. Single IPs only, at most 20 per run, and every action is logged and notified.
Fetches Spamhaus DROP · FireHOL level1 once a day and applies them to every server. Entries that overlap your own ranges are filtered out first.
Adds the ranges of the countries you choose to a dedicated list in your servers’ firewalls. Turning it off empties only that list — other blocks stay as they are.
Report only banned IPs to AbuseIPDB and look up their reputation. Automatic blocks and list changes are announced on Telegram. Keys stay on the console server only.
Every enforcement action, report and login is recorded. Three roles — viewer · operator · administrator — plus TOTP two-factor authentication.
The console never pushes commands to your servers. The agent on each server connects out to the console first, uploads its status, picks up signed commands, verifies them itself and only then runs them.
SecuMon uses its own nftables table that never mixes with fail2ban’s rules. Blocks are split into three layers so you can always tell “why it was blocked”, and updating one layer leaves the others untouched.
Built so that a tool you add to protect your servers doesn’t become a new hole.
Coming soonInstaller downloads are still being prepared.
In the meantime, check the requirements and installation steps in the free guide.
From prerequisites to your first block, step by step, starting with a single personal server.
It also covers what you must know before turning on country blocking.
Questions? halo@levelupsoft.com