## /etc/fail2ban/filter.d/nginx-bad-req.conf
# fail2ban filter configuration for nginx
[Definition]
failregex = ^<HOST> .* "(GET|POST|HEAD).*HTTP.*" 500 .*$
### /etc/fail2ban/jail.local
[nginx-bad-req]
enabled = true
port = http,https
filter = nginx-bad-req
logpath = %(nginx_access_log)s
maxretry = 10
findtime = 60
bantime = 3600
ignoreip = 127.0.0.1