Should I Keep Fail2ban Enabled with Cloudflare?

0
10
Asked By ArtisticWanderer92 On

I recently set up a VPS to build a personal art blog using Django with HTML, JavaScript, and CSS. I originally configured Fail2ban to monitor my Nginx logs and block IPs attempting to hack into my site, even though it's not a WordPress site. Now that I've also signed up for Cloudflare to experiment with features like Turnstile on my web forms, I'm wondering if I should disable Fail2ban for my Nginx logs (ports 80 and 443). Does Cloudflare take care of banning suspicious IPs for me, or should I keep Fail2ban active to protect against unwanted traffic? Will Cloudflare reduce the number of bot requests I receive?

2 Answers

Answered By SecureConnection88 On

Just to clarify, if you're using SSH keys and programs like knockd to limit access to port 22, that adds extra protection. You still want Fail2ban for your Nginx logs, especially since Cloudflare won't handle those specific logs for you. Keeping it active is a smart move!

Answered By WebGuardian2023 On

You should definitely keep Fail2ban enabled. Cloudflare doesn't automatically ban IPs; it's more about protecting your site at a different level. To enhance your security, consider setting up WAF rules in Cloudflare to block certain countries or ASNs that shouldn't be accessing your site.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.