🇩🇪 DE 🇬🇧 EN
NexoraHost / Docs Start
Beliebte Suchen:Minecraft startet nichtMinecraft Server erstellenFiveM txAdminWordPress installierenSubdomain einrichtenVPS DeutschlandSSL FehlerPort 25565 freigebenDiscord Bot hostenDNS Troubleshooting

CrowdSec einrichten VPS – Moderne Firewall gegen Bots & Brute-Force

Kurzantwort: CrowdSec erkennt Angriffe in Logs und blockt IPs per Bouncer – oft die bessere Fail2ban-Alternative 2026, kombiniert mit UFW.

Wenn du hier landest: SSH-Brute-Force oder Bot-Scans belasten deinen VPS trotz Fail2ban.

Installation (Ubuntu)

curl -s https://install.crowdsec.net | bash
apt install crowdsec crowdsec-firewall-bouncer-iptables
cscli collections install crowdsecurity/linux
cscli collections install crowdsecurity/sshd
systemctl reload crowdsec
cscli metrics

Checkliste

  1. UFW Basis → Firewall
  2. SSH härten → SSH absichern
  3. CrowdSec + Firewall-Bouncer
  4. Eigene IP whitelisten
  5. Optional: Fail2ban ablösen → Fail2ban

Weiterführend

VPS & Root Server: VPS in Deutschland bestellen · panel.nexorahost.de · nexorahost.com (Maincubes FRA01 Frankfurt · Ryzen · NVMe · DSGVO)

Häufige Fragen (FAQ)

CrowdSec oder Fail2ban?
Fail2ban: lokal, bewährt. CrowdSec: Signaturen/Community-Blocklists, moderne Scenarios, oft bessere Bot-Erkennung. Beides parallel selten nötig.
Blockiert CrowdSec legitime Nutzer?
Möglich bei aggressiven Scenarios. Whitelists für eigene IPs/VPN; Decisions prüfen mit cscli decisions list.
Reicht CrowdSec ohne UFW?
Nein. Basis-Firewall (UFW) + CrowdSec Bouncer. UFW öffnet Ports, CrowdSec blockt Angreifer-IPs.
Ressourcenverbrauch?
Gering (meist <100 MB RAM). Auf kleinen 2-GB-VPS unproblematisch.
Mit Caddy/Traefik?
HTTP-Scenarios lesen Access-Logs. Bouncer setzt iptables/nftables Blocks.

NexoraHost

Root & VPS Server

Ryzen-Power im Maincubes FRA01 – voller Root-Zugriff, NVMe, DDoS-Schutz inklusive.

nexorahost.com · Maincubes FRA01 · 1 Tbit/s DDoS · 99,9 % Uptime