BanGuardian
A central control plane that turns Fail2ban events into network-edge enforcement through OPNsense instead of leaving every server to defend itself in isolation.
The problem behind the system.
Fail2ban is excellent at spotting abusive behaviour, but bans normally remain local to the machine that detected it. I wanted detections across services to become useful at the firewall too.
How I approached it.
- A Spring Boot service that receives ban/unban events and synchronises them with OPNsense aliases.
- A single place to inspect and control the security state instead of treating hosts as isolated islands.
- An API-driven design that can grow into a broader security dashboard and policy layer.
What the system enabled.
The project turned a collection of independent host-level bans into shared network-edge enforcement and gave me a practical playground for security automation.