Use fail2ban to protect Magento admin panel

So, since my wp-login guide seems to have helped a few out there, I’ve modified it to work for Magento’s Admin panel. This guide assumes use of Apache and CentOS.

Install fail2ban if it is not installed already, then add this configuration file:

and these contents:

failregex = ^<HOST> -.*POST \/index.php\/admin\/.*
ignoreregex =
Append or add this file:

and the contents:

enabled = true
filter = magento-admin
action = iptables-multiport[name=NoAuthFailures, port=”https,https”]
logpath = /var/log/httpd/*access*.log
findtime = 60
bantime = 86400
maxretry = 3

fail2ban uses the sites access logs to check. This is set up to check all access logs in the /var/log/httpd folder. Adjust this rule based on your server’s log location and configuration (not the wildcard *).

Finally restart fail2ban

service fail2ban restart


systemctl restart fail2ban


Thor swings that ban hammer!


Leave a Reply

Your email address will not be published. Required fields are marked *