Use CrowdSec for Linux Host Firewall Remediation
CrowdSec separates log analysis from enforcement. The Security Engine parses configured logs and creates decisions; a remediation component applies those decisions. This walkthrough uses the firewall bouncer for host-level IP blocking on Debian or Ubuntu. It is not a web application firewall.
The commands can change firewall rules. Test on a maintenance window, confirm your existing firewall and remote-access recovery path, and review the bouncer’s managed rules before using it on a production host.
Step 1: Install the CrowdSec Security Engine
Add the Official Repository and Install CrowdSec
Engine SetupRun these commands on a supported Debian or Ubuntu host. The official repository bootstrap installs the package source; review your organization’s software-source policy before running it. The Security Engine detects activity but does not block traffic on its own.
curl -s https://install.crowdsec.net | sudo shsudo apt updatesudo apt install crowdsecsudo systemctl status crowdsec --no-pager❯ View Expected Console Output
crowdsec.service - CrowdSec agentActive: active (running)Step 2: Configure SSH Log Detection
Install the SSH Collection and Confirm Log Input
Log DetectionInstall the SSH parser and detection scenarios. This example assumes Debian or Ubuntu writes SSH authentication events to readable /var/log/auth.log; inspect existing acquisitions first so the same file is not read twice. If your host uses journald only or a different path, do not add the file-based acquisition below; configure the actual source using CrowdSec’s acquisition guide.
sudo test -r /var/log/auth.log && echo 'auth.log is readable' || echo 'auth.log is missing or unreadable'sudo find /etc/crowdsec -maxdepth 2 -type f -name '*.yaml' -printsudo grep -R -n -E '/var/log/auth\.log|type: syslog' /etc/crowdsec/acquis.yaml /etc/crowdsec/acquis.d/ 2>/dev/null || truesudo cscli collections install crowdsecurity/sshd❯ View Expected Console Output
auth.log is readablecrowdsecurity/sshd: enabledIf no existing acquisition already covers /var/log/auth.log, create /etc/crowdsec/acquis.d/ssh.yaml:
sudo install -d -m 0755 /etc/crowdsec/acquis.dsudo tee /etc/crowdsec/acquis.d/ssh.yaml >/dev/null <<'EOF'filenames: - /var/log/auth.loglabels: type: syslogEOFThen validate the configuration and restart the engine to apply the change:
sudo crowdsec -tsudo systemctl restart crowdsecStep 3: Install the Firewall Bouncer for Your Backend
Choose the Matching Host Firewall Package
IP RemediationCheck the active firewall backend, then install its matching package. The bouncer applies IP decisions to the host firewall and may add managed chains or sets. Review the existing firewall rules and test access to SSH before proceeding, especially on remotely managed systems.
❯ View Expected Console Output
Firewall bouncer package installed and registered with the local CrowdSec API.When iptables is available, run iptables -V. If the output contains nf_tables, select the nftables package. Select the iptables package only when the host uses the legacy iptables/ipset backend; if the backend is unclear, check the distribution’s firewall configuration before installing a bouncer. If the package does not register or start the bouncer automatically, follow the package’s service instructions and confirm its local API registration before relying on enforcement.
Step 4: Verify Acquisition, Decisions, and Bouncer Health
Check Parsed Logs and Firewall Bouncer Status
VerificationConfirm CrowdSec is reading and parsing the expected authentication log, then check that the firewall bouncer is healthy. A new installation may have no active decisions; an empty decision list is normal until a detection matches. Do not create a test ban on a production host just to populate this output.
sudo cscli metricssudo cscli metrics show bouncerssudo cscli decisions listsudo cscli bouncers listsudo systemctl --no-pager --type=service --state=running | grep -E 'crowdsec'❯ View Expected Console Output
Acquisition metrics show auth.log being read; SSH parser counters increase when matching events are present.Bouncer metrics show the last successful API pull.No active decisionsBouncer is registered; its service is running.