Ask Steves · Daily notes · VPS, 20% off · AI Profit Lab · SEO · Money Hub

5 October 2026 · One command a day

How do I see which IPs fail2ban has banned?

The command fail2ban-client status sshd shows what fail2ban is doing about failed SSH logins on your server. It lists the addresses that are banned right now, how many it has banned in total, and how many failed attempts it has counted. You reach for it when you want proof that the brute-force attempts hitting every public server are actually being blocked.

The command

sudo fail2ban-client status sshd

sudo is needed because the client talks to the fail2ban service through a socket that only root can use. fail2ban-client is the tool for asking the running service questions and giving it instructions. status asks for a report, and sshd is the name of the jail you want the report on. A jail pairs a log to watch with an action to take, and sshd is the one Ubuntu enables by default when you install fail2ban.

What you will see

Status for the jail: sshd
|- Filter
|  |- Currently failed: 3
|  |- Total failed:     1842
|  `- Journal matches:  _SYSTEMD_UNIT=sshd.service + _COMM=sshd
`- Actions
   |- Currently banned: 2
   |- Total banned:     127
   `- Banned IP list:   203.0.113.45 198.51.100.7

The Filter half is about what fail2ban has read. Currently failed is the number of addresses that have failed recently but have not yet reached the ban threshold. Total failed is every failed attempt it has matched since the service last started. The Actions half is about what it did in response. Currently banned and the Banned IP list are the addresses blocked at this moment, and Total banned is the running count since the last restart. The line under the filter tells you where it reads from, which on Ubuntu 24.04 is normally the systemd journal rather than a log file.

When to use it

Watch out for

Both totals reset to zero when the fail2ban service restarts, so a low number does not mean a quiet server if it was restarted this morning. Bans also expire. The default ban time is ten minutes, so an address that was in the list an hour ago may be gone now even though it was banned. If the command says the jail does not exist, the sshd jail is not enabled. If it complains about permission on the socket, you have forgotten sudo. If it cannot connect at all, check that the service is running first.

Questions people ask

How do I see why an IP address was banned?

The status output only shows who. For the why, search the fail2ban log with sudo grep 203.0.113.45 /var/log/fail2ban.log, which shows each failed attempt it matched and the moment it banned the address.

How do I unban an address?

Run sudo fail2ban-client set sshd unbanip 203.0.113.45, replacing the address with the one you need. The ban is lifted at once, but the same address will be banned again if it keeps failing.

Checking who is being kept out of your server, and letting the right person back in, is only possible on a server you control. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.

Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.

GET A VPS, 20% OFF →

Affiliate link.

More daily notes: How do I list ufw firewall rules with numbers on Ubuntu? · How do I list all my SSL certificates and their expiry dates with certbot? · How do I test that certbot can renew my SSL certificate?