Brute-force attacks targeting database authentication are common when ports are exposed or accessible from untrusted networks. This guide walks through configuring a custom Fail2Ban filter to monitor MSSQL login failures, setting up the jail, ensuring service persistence across system reboots, and verifying your active bans.
Step 1: Create a Custom Fail2Ban Filter for MSSQL
By default, Fail2Ban does not know how to parse Microsoft SQL Server authentication failure logs. You need to define a custom filter pattern.
1.Create the Filter File:1 min.
Create and open a new filter configuration file using nano:
Bash
sudo nano /etc/fail2ban/filter.d/mssql-auth.conf
Verification: Ensure the file opens successfully in the editor.
2.Add the Detection Rules:1 min.
Paste the following clean configuration into the file, save, and exit:
Ini, TOML
[Definition]
failregex = Login failed for user.*\[CLIENT: <HOST>\]
ignoreregex =
Verification: Run sudo fail2ban-client --test to verify that there are no syntax errors in your filter configuration.
Step 2: Configure the Fail2Ban Jail
Next, create or update your local jail configuration to instruct Fail2Ban to monitor your MSSQL log path using the filter you just created.
1.Edit jail.local:1 min.
Open your local Fail2Ban jail configuration file:
Bash
sudo nano /etc/fail2ban/jail.local
2.Define the mssql-auth Jail Block:1 min.
Add the following block to the bottom of the file:
Ini, TOML
[mssql-auth]
enabled = true
port = 1433
filter = mssql-auth
logpath = /var/opt/mssql/log/errorlog
maxretry = 5
findtime = 600
bantime = 3600
(Note: Adjust the logpath if your MSSQL error log resides in a custom or containerized location).
Verification: Save the file and run sudo fail2ban-client --test again to ensure all jails parse correctly.
Step 3: Make the Service Persistent on Boot
To ensure Fail2Ban automatically launches and protects your server whenever it restarts, enable its systemd service.
1.Enable and Start Fail2Ban:30 sec.
Run the following commands to start the service and make it persistent across system reboots:
Bash
sudo systemctl start fail2ban
sudo systemctl enable fail2ban
Verification: Run sudo systemctl is-enabled fail2ban to confirm it returns enabled.
Step 4: Verify Service Status and Banned IPs
Once your service is active and running, you can monitor its operation and check for any blocked brute-force actors.
1.Check Jail Status:30 sec.
Query the status of your MSSQL jail via the client utility:
Bash
sudo fail2ban-client status mssql-auth
Verification: Review the output under Banned IP list to see any currently restricted malicious client addresses.

Join the conversation! Your thoughts help the community grow.