<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Daniel Black</title>
    <description>The latest articles on DEV Community by Daniel Black (@danielblack).</description>
    <link>https://dev.to/danielblack</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4173074%2Fedeece9d-c343-47a9-b00c-412ccba2eb3f.jpeg</url>
      <title>DEV Community: Daniel Black</title>
      <link>https://dev.to/danielblack</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/danielblack"/>
    <language>en</language>
    <item>
      <title>Hardening a Server in Two Steps: Fail2ban for the Host, SafeLine for the App</title>
      <dc:creator>Daniel Black</dc:creator>
      <pubDate>Fri, 09 Oct 2026 11:23:38 +0000</pubDate>
      <link>https://dev.to/danielblack/hardening-a-server-in-two-steps-fail2ban-for-the-host-safeline-for-the-app-2i12</link>
      <guid>https://dev.to/danielblack/hardening-a-server-in-two-steps-fail2ban-for-the-host-safeline-for-the-app-2i12</guid>
      <description>&lt;p&gt;People treat server hardening and web-app protection as two separate projects. They aren't. Fail2ban and SafeLine cover different layers, and together they take about ten minutes to stand up. Here's the two-step version.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 1 — Fail2ban: lock down the host
&lt;/h2&gt;

&lt;p&gt;Fail2ban watches your server's logs and bans IPs that show hostile behavior — SSH brute force, repeated 404s, port scans. Install it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo &lt;/span&gt;apt &lt;span class="nb"&gt;install &lt;/span&gt;fail2ban
&lt;span class="nb"&gt;sudo &lt;/span&gt;systemctl &lt;span class="nb"&gt;enable&lt;/span&gt; &lt;span class="nt"&gt;--now&lt;/span&gt; fail2ban
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;By default it protects SSH. Enable a few more jails (nginx, wordpress) and bad actors get dropped at the firewall before they ever reach your app.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 2 — SafeLine: protect the app
&lt;/h2&gt;

&lt;p&gt;SafeLine sits in front of your web app as a reverse proxy and inspects every HTTP request. Install it in one command:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Point it at your app via the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;. SQL injection, XSS, and malicious bots get blocked at the application layer — even from an IP with a clean reputation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why both
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Fail2ban&lt;/strong&gt; stops host-level noise: SSH brute force, scanning, repeated probes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SafeLine&lt;/strong&gt; stops app-level attacks: injection, XSS, malicious bots reaching your code.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;One guards the door; the other guards what's inside. Neither replaces the other.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does Fail2ban need SafeLine?
&lt;/h3&gt;

&lt;p&gt;If your only risk is SSH brute force, Fail2ban alone is a fine start. But it can't see into HTTP request bodies — that's SafeLine's job.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does SafeLine need Fail2ban?
&lt;/h3&gt;

&lt;p&gt;SafeLine protects the app, not the host. Without Fail2ban, your SSH port and other services stay exposed to brute force.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is SafeLine open source?
&lt;/h3&gt;

&lt;p&gt;SafeLine is a self-hosted WAF with a free Community Edition (up to 10 apps, 800 QPS). It's not open source — you run it yourself rather than building from source.&lt;/p&gt;

&lt;h3&gt;
  
  
  How long does setup take?
&lt;/h3&gt;

&lt;p&gt;About ten minutes for both, most of it waiting on package installs.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Two steps, two layers, one quieter server.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>fail2ban</category>
      <category>security</category>
      <category>application</category>
      <category>selfhosted</category>
    </item>
    <item>
      <title>SafeLine + CrowdSec: Building a Two-Layer Defense for Your Server</title>
      <dc:creator>Daniel Black</dc:creator>
      <pubDate>Fri, 09 Oct 2026 11:06:14 +0000</pubDate>
      <link>https://dev.to/danielblack/safeline-crowdsec-building-a-two-layer-defense-for-your-server-4e61</link>
      <guid>https://dev.to/danielblack/safeline-crowdsec-building-a-two-layer-defense-for-your-server-4e61</guid>
      <description>&lt;p&gt;People often frame SafeLine and CrowdSec as an either/or choice. They aren't. One guards your application layer, the other guards your server's perimeter — and a real defense is usually both. Here's how the two fit together in practice, without doubling your workload.&lt;/p&gt;

&lt;h2&gt;
  
  
  The idea in one paragraph
&lt;/h2&gt;

&lt;p&gt;CrowdSec watches your whole server and bans IPs that misbehave. SafeLine sits in front of your web app and filters malicious HTTP requests before they reach your code. Stack them and you get &lt;strong&gt;IP reputation at the edge&lt;/strong&gt; plus &lt;strong&gt;payload inspection at the app&lt;/strong&gt; — two layers, one quiet server.&lt;/p&gt;

&lt;h2&gt;
  
  
  A concrete topology
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Internet
   │
   ▼
CrowdSec  (agent + firewall bouncer: bans known-bad / scanning IPs)
   │
   ▼
SafeLine  (reverse proxy: inspects every HTTP request)
   │
   ▼
Your app
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;CrowdSec acts first, at the network level. Anything that survives gets handed to SafeLine, which inspects what's actually being requested.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where each one actually acts
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;CrowdSec&lt;/strong&gt; sees the &lt;em&gt;IP&lt;/em&gt;, the request volume, and behavior patterns (scanning, credential guessing, weird paths). It bans at the firewall, so bad actors never waste your resources.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SafeLine&lt;/strong&gt; sees the &lt;em&gt;request body&lt;/em&gt;. It catches SQL injection, XSS, and malicious bots using a semantic engine that understands what a request is trying to do — even from an IP with a spotless reputation.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  A realistic scenario
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Case A — the noisy scanner.&lt;/strong&gt; An IP floods your site with probes. CrowdSec recognizes the scan behavior (and may already know the IP from its global threat feed), bans it at the firewall. The traffic never reaches SafeLine.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Case B — the patient attacker.&lt;/strong&gt; A fresh IP, clean reputation, sends a seemingly normal POST with a hidden SQLi payload. CrowdSec sees nothing wrong with the IP, so it passes. The request hits SafeLine, whose semantic engine flags the injection and drops it.&lt;/p&gt;

&lt;p&gt;Neither tool alone covers both cases. Together, they do.&lt;/p&gt;

&lt;h2&gt;
  
  
  Getting both running
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;SafeLine&lt;/strong&gt; installs in one command and runs as a reverse proxy in front of your app:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Point it at your app via the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, and your HTTP traffic is filtered.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CrowdSec&lt;/strong&gt; installs as an agent plus a "bouncer" that enforces bans in your firewall (iptables/nftables). Add the collections for the services you actually run, and it starts learning behavior immediately.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Will they conflict?
&lt;/h3&gt;

&lt;p&gt;No. CrowdSec manages firewall rules on the host; SafeLine manages a reverse proxy in front of the app. Different layers, no overlap.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need CrowdSec if I already have SafeLine?
&lt;/h3&gt;

&lt;p&gt;SafeLine alone leaves host-level threats (SSH brute force, port scanning) unaddressed. CrowdSec covers that gap.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is CrowdSec open source?
&lt;/h3&gt;

&lt;p&gt;Yes — it's open-source and community-driven, sharing threat signals across its network. SafeLine is a self-hosted WAF you run yourself, with a free Community Edition covering up to 10 apps at 800 QPS.&lt;/p&gt;

&lt;h3&gt;
  
  
  Which should I install first?
&lt;/h3&gt;

&lt;p&gt;Start with SafeLine if your priority is the web app; add CrowdSec when you want host-level IP banning too. Order doesn't matter much.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Stop choosing between layers. Run them both and let each do what it's best at.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>waf</category>
      <category>security</category>
      <category>devops</category>
      <category>crowdsec</category>
    </item>
  </channel>
</rss>
