Skip to content

Use CrowdSec for Linux Host Firewall Remediation

CrowdSec separates log analysis from enforcement. The Security Engine parses configured logs and creates decisions; a remediation component applies those decisions. This walkthrough uses the firewall bouncer for host-level IP blocking on Debian or Ubuntu. It is not a web application firewall.

The commands can change firewall rules. Test on a maintenance window, confirm your existing firewall and remote-access recovery path, and review the bouncer’s managed rules before using it on a production host.


Step 1: Install the CrowdSec Security Engine

01

Add the Official Repository and Install CrowdSec

Engine Setup

Run these commands on a supported Debian or Ubuntu host. The official repository bootstrap installs the package source; review your organization’s software-source policy before running it. The Security Engine detects activity but does not block traffic on its own.

Terminal window
curl -s https://install.crowdsec.net | sudo sh
sudo apt update
sudo apt install crowdsec
sudo systemctl status crowdsec --no-pager
❯ View Expected Console Output
crowdsec.service - CrowdSec agent
Active: active (running)

Step 2: Configure SSH Log Detection

02

Install the SSH Collection and Confirm Log Input

Log Detection

Install the SSH parser and detection scenarios. This example assumes Debian or Ubuntu writes SSH authentication events to readable /var/log/auth.log; inspect existing acquisitions first so the same file is not read twice. If your host uses journald only or a different path, do not add the file-based acquisition below; configure the actual source using CrowdSec’s acquisition guide.

Terminal window
sudo test -r /var/log/auth.log && echo 'auth.log is readable' || echo 'auth.log is missing or unreadable'
sudo find /etc/crowdsec -maxdepth 2 -type f -name '*.yaml' -print
sudo grep -R -n -E '/var/log/auth\.log|type: syslog' /etc/crowdsec/acquis.yaml /etc/crowdsec/acquis.d/ 2>/dev/null || true
sudo cscli collections install crowdsecurity/sshd
❯ View Expected Console Output
auth.log is readable
crowdsecurity/sshd: enabled

If no existing acquisition already covers /var/log/auth.log, create /etc/crowdsec/acquis.d/ssh.yaml:

Terminal window
sudo install -d -m 0755 /etc/crowdsec/acquis.d
sudo tee /etc/crowdsec/acquis.d/ssh.yaml >/dev/null <<'EOF'
filenames:
- /var/log/auth.log
labels:
type: syslog
EOF

Then validate the configuration and restart the engine to apply the change:

Terminal window
sudo crowdsec -t
sudo systemctl restart crowdsec

Step 3: Install the Firewall Bouncer for Your Backend

03

Choose the Matching Host Firewall Package

IP Remediation

Check the active firewall backend, then install its matching package. The bouncer applies IP decisions to the host firewall and may add managed chains or sets. Review the existing firewall rules and test access to SSH before proceeding, especially on remotely managed systems.

Terminal window
sudo apt install crowdsec-firewall-bouncer-nftables
❯ View Expected Console Output
Firewall bouncer package installed and registered with the local CrowdSec API.

When iptables is available, run iptables -V. If the output contains nf_tables, select the nftables package. Select the iptables package only when the host uses the legacy iptables/ipset backend; if the backend is unclear, check the distribution’s firewall configuration before installing a bouncer. If the package does not register or start the bouncer automatically, follow the package’s service instructions and confirm its local API registration before relying on enforcement.


Step 4: Verify Acquisition, Decisions, and Bouncer Health

04

Check Parsed Logs and Firewall Bouncer Status

Verification

Confirm CrowdSec is reading and parsing the expected authentication log, then check that the firewall bouncer is healthy. A new installation may have no active decisions; an empty decision list is normal until a detection matches. Do not create a test ban on a production host just to populate this output.

Terminal window
sudo cscli metrics
sudo cscli metrics show bouncers
sudo cscli decisions list
sudo cscli bouncers list
sudo systemctl --no-pager --type=service --state=running | grep -E 'crowdsec'
❯ View Expected Console Output
Acquisition metrics show auth.log being read; SSH parser counters increase when matching events are present.
Bouncer metrics show the last successful API pull.
No active decisions
Bouncer is registered; its service is running.

Comments