Dev.to Security ๐Ÿ” Cybersecurity ๐Ÿ‘ 0 ๐Ÿ“– 2 min read

Hardening a Server in Two Steps: Fail2ban for the Host, SafeLine for the App

People treat server hardening and web-app protection as two separate projects. They aren't. Fail2ban and SafeLine cover different layers, and together they take about ten minutes to stand up. Here's the two-step version.

People treat server hardening and web-app protection as two separate projects. They aren't. Fail2ban and SafeLine cover different layers, and together they take about ten minutes to stand up. Here's the two-step version.

Step 1 โ€” Fail2ban: lock down the host

Fail2ban watches your server's logs and bans IPs that show hostile behavior โ€” SSH brute force, repeated 404s, port scans. Install it:

sudo apt install fail2ban
sudo systemctl enable --now fail2ban

By default it protects SSH. Enable a few more jails (nginx, wordpress) and bad actors get dropped at the firewall before they ever reach your app.

Step 2 โ€” SafeLine: protect the app

SafeLine sits in front of your web app as a reverse proxy and inspects every HTTP request. Install it in one command:

bash -c "$(curl -fsSLk https://waf.chaitin.com/release/latest/manager.sh)" -- --en

Point it at your app via the console at https://<your-server-ip>:9443. SQL injection, XSS, and malicious bots get blocked at the application layer โ€” even from an IP with a clean reputation.

Why both

  • Fail2ban stops host-level noise: SSH brute force, scanning, repeated probes.
  • SafeLine stops app-level attacks: injection, XSS, malicious bots reaching your code.

One guards the door; the other guards what's inside. Neither replaces the other.

FAQ

Does Fail2ban need SafeLine?

If your only risk is SSH brute force, Fail2ban alone is a fine start. But it can't see into HTTP request bodies โ€” that's SafeLine's job.

Does SafeLine need Fail2ban?

SafeLine protects the app, not the host. Without Fail2ban, your SSH port and other services stay exposed to brute force.

Is SafeLine open source?

SafeLine is a self-hosted WAF with a free Community Edition (up to 10 apps, 800 QPS). It's not open source โ€” you run it yourself rather than building from source.

How long does setup take?

About ten minutes for both, most of it waiting on package installs.

Two steps, two layers, one quieter server.

  • โญ SafeLine WAF on GitHub โ€” give it a star if you find it useful
  • ๐Ÿ”— Official Docs โ€” installation guide, configuration, and API reference
  • ๐Ÿงช Live Demo โ€” see the dashboard in action (no login required)
๐Ÿ“ฐ Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.