Brute-force attacks targeting database authentication are common when ports are exposed or accessible from untrusted networks. This guide walks through configuring a custom Fail2Ban filter to monitor MSSQL login failures, setting up the jail, ensuring service persistence across system reboots, and verifying your active bans.

Step 1: Create a Custom Fail2Ban Filter for MSSQL

By default, Fail2Ban does not know how to parse Microsoft SQL Server authentication failure logs. You need to define a custom filter pattern.

1.Create the Filter File:1 min.

Create and open a new filter configuration file using nano:

Bash

sudo nano /etc/fail2ban/filter.d/mssql-auth.conf

Verification: Ensure the file opens successfully in the editor.

2.Add the Detection Rules:1 min.

Paste the following clean configuration into the file, save, and exit:

Ini, TOML

[Definition]
failregex = Login failed for user.*\[CLIENT: <HOST>\]
ignoreregex =

Verification: Run sudo fail2ban-client --test to verify that there are no syntax errors in your filter configuration.

Step 2: Configure the Fail2Ban Jail

Next, create or update your local jail configuration to instruct Fail2Ban to monitor your MSSQL log path using the filter you just created.

1.Edit jail.local:1 min.

Open your local Fail2Ban jail configuration file:

Bash

sudo nano /etc/fail2ban/jail.local

2.Define the mssql-auth Jail Block:1 min.

Add the following block to the bottom of the file:

Ini, TOML

[mssql-auth]
enabled = true
port = 1433
filter = mssql-auth
logpath = /var/opt/mssql/log/errorlog
maxretry = 5
findtime = 600
bantime = 3600

(Note: Adjust the logpath if your MSSQL error log resides in a custom or containerized location).

Verification: Save the file and run sudo fail2ban-client --test again to ensure all jails parse correctly.

Step 3: Make the Service Persistent on Boot

To ensure Fail2Ban automatically launches and protects your server whenever it restarts, enable its systemd service.

1.Enable and Start Fail2Ban:30 sec.

Run the following commands to start the service and make it persistent across system reboots:

Bash

sudo systemctl start fail2ban
sudo systemctl enable fail2ban

Verification: Run sudo systemctl is-enabled fail2ban to confirm it returns enabled.

Step 4: Verify Service Status and Banned IPs

Once your service is active and running, you can monitor its operation and check for any blocked brute-force actors.

1.Check Jail Status:30 sec.

Query the status of your MSSQL jail via the client utility:

Bash

sudo fail2ban-client status mssql-auth

Verification: Review the output under Banned IP list to see any currently restricted malicious client addresses.