// Engineering Log
Securing a Linux Server: Part 3 — CrowdSec
Published on 2026-09-22
// Fast route
This article belongs to the topic Servers and infrastructure.
Fail2ban protects each server individually: it only sees its own logs and doesn’t know that the same addresses attacked thousands of other machines a minute ago. CrowdSec solves the same problem — detect attacks from logs and block the address — but adds to the local analysis a shared list of attacking addresses collected by all its users.
CrowdSec is distributed under the MIT license. Current version — 1.8.1 (03.09.2026).
How CrowdSec is organized
The CrowdSec documentation uses the following concepts:
- Security Engine — the detection system itself. It consists of a log handler (Log Processor, often called the agent) and a Local API.
- Log Processor reads service logs and HTTP requests, parses them with parsers and matches them against scenarios — descriptions of malicious behavior: password guessing, scanning, searching for vulnerable paths on a site.
- Local API (LAPI) stores blocking decisions and distributes them to remediation components. Through it the Security Engine also exchanges data with the central CrowdSec API.
- Remediation Components (they are called bouncers) — separate programs that receive decisions from the LAPI and perform blocking: in the firewall, in the web server, in the reverse proxy.
- Collections — ready-made sets of parsers and scenarios for a specific service (SSH, Nginx, Postfix, etc.). They are stored in the Hub catalog.
- Console — web interface for viewing alerts and blocks from all connected servers.
An important detail explicitly stated in the documentation: the Security Engine by itself doesn’t block anything — it’s only a detection system. Without a remediation component CrowdSec will detect attacks but let attackers through.
Shared list of attackers
When your server detects an attack, it sends a signal — the address and the triggered scenario — to the central API. From the signals of thousands of CrowdSec installations the Community Blocklist is compiled and distributed to participants. The conditions depend on contribution level:
- those who regularly send signals receive the full list — up to 15,000 addresses, selected by scenarios that appear on your host;
- those who do not send signals receive a reduced version — up to 3,000 addresses;
- paid plans provide up to 60,000 addresses.
This way the server preemptively blocks addresses that have not yet attacked it specifically but have already been seen on other machines.
Installation on Debian and Ubuntu
curl -s https://install.crowdsec.net | sudo sh
sudo apt install crowdsec
sudo apt install crowdsec-firewall-bouncer-nftables # or -iptablesThe first command adds the CrowdSec repository, the second installs the Security Engine, the third installs the remediation component for the firewall. During installation CrowdSec tries to detect running services and automatically installs appropriate parsers and scenarios. If some service is not detected, its log is added to the sources settings manually and the required collection is installed:
sudo cscli collections list
sudo cscli collections install crowdsecurity/nginx
sudo systemctl reload crowdsecFirst commands
sudo cscli metrics # what is being read and what is triggering
sudo cscli alerts list # detected attacks
sudo cscli decisions list # active block decisions
sudo cscli decisions delete --ip 203.0.113.10 # remove block
sudo cscli console enroll <key> # enroll server to Consolecscli metrics is the main diagnostic command: if it doesn’t show lines for the desired log, CrowdSec isn’t reading it and that service is not protected.
Whitelists
Before enabling blocking, add your addresses to the whitelist: office, monitoring servers, addresses used by administrators. The documentation specifically recommends this step — a false positive on your own monitoring will block it just like a bot.
How CrowdSec differs from Fail2ban
| Fail2ban | CrowdSec | |
|---|---|---|
| Detection | regular expressions against logs | parsers and behavior scenarios |
| Blocking | action inside Fail2ban | separate remediation components |
| Where to block | server firewall | firewall, web server, proxy, CDN |
| Awareness of attacks on other machines | no | shared list of attackers |
| Multiple servers | each on its own | one LAPI and Console for all |
| Resources | minimal | more, but moderate |
For a single server with SSH, Fail2ban is sufficient. CrowdSec makes sense when there are multiple servers, when you need to protect web applications by behavior rather than only by failed logins, and when you want to block known attackers before the first attempt.
Running Fail2ban and CrowdSec simultaneously for the same logs doesn’t make sense: they will duplicate blocks and it will become harder to figure out who blocked an address. Usually one is chosen.
Common mistakes
- Only the Security Engine is installed without a remediation component — attacks are visible in
cscli alerts, but nothing is blocked. - Own addresses and monitoring are not added to the whitelist.
- The service writes logs to a non-standard location, CrowdSec doesn’t read it, and the administrator assumes the service is protected. Check with
cscli metrics. - The remediation component is chosen for the wrong firewall (iptables instead of nftables).
- Collections are not updated: scenarios in the Hub are regularly extended — update with
cscli hub updateandcscli hub upgrade.
How to integrate CrowdSec into the overall protection setup of a new server is described in the article “A new server is not a blank slate”.
// Similar task
If you are dealing with something similar
This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.
Article topic
Servers and infrastructure
VPS, Linux, web stack, migrations, hosting, databases, and core operations.
Typical tasks behind this topic
- Move a site or service to a new server
- Set up Linux, Nginx, databases, and backups
- Figure out why the system behaves unstably
// Next step
If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.
Open services// Reviews
Related reviews
I came with an expensive request to configure a VPS server, but during the consultation Mikhail suggested a much simpler, more affordable solution. In the end I saved time and money. Mikhail — a true expert who works for the client's result, not for the fee. I recommend him!
I came with an expensive request to configure a VPS server, but during the consultation Mikhail suggested a much simpler and more cost-effective solution. In the end I saved budget and time. Mikhail — a true expert who …
VPS setup, server setup
2026-05-12 · ★ 5/5
Excellent work! Set up the server very quickly, installed the control panel, and configured the IP. Definitely recommend!
Excellent work! Very quickly set up the server, installed the panel, configured the IP I can definitely recommend it!
Everything was excellent; helped promptly and professionally. Thank you — I recommend them to the community.
Everything's great, helped promptly and professionally, thank you, I recommend it to the community
VPS setup, server setup
2026-04-16 · ★ 5/5
There were several issues concerning both the technical side and overall understanding. Mikhail responded quickly, resolved the technical problems, and helped me understand them — many thanks. I'm satisfied with the result.
There were several issues concerning both the technical side and overall understanding. Mikhail responded quickly to the request, helped sort things out and resolved the technical problems and helped clarify …
VPS setup, server setup
2026-02-18 · ★ 5/5
Everything was done quickly and efficiently. I recommend.
Everything was done quickly and efficiently. I recommend.
VPS setup, server setup
2026-01-17 · ★ 5/5
Everything went well; the contractor responded quickly to questions and helped resolve the issue. Thanks!
Everything went well, the contractor responded quickly to questions and helped resolve the issue. Thank you!
VPS setup, server setup
2025-12-16 · ★ 5/5
// Contact
Need help?
Get in touch with me and I'll help solve the problem
I reply within one business day (03:00-13:00 GMT)
Или оставьте заявку здесь:
// Related