Hostxpeed
Login Get Started →
Security

How to Detect Port Scanning

4 min read
31 views
Jun 13, 2026

Method 1: Using Fail2ban Port Scan Jail

sudo nano /etc/fail2ban/jail.local

Add:

[scan]
enabled = true
port = any
filter = scan
logpath = /var/log/auth.log
maxretry = 2
bantime = 86400

Method 2: Detect with tcpdump

sudo tcpdump -i eth0 'tcp[tcpflags] & (tcp-syn) != 0 and not tcp[tcpflags] & (tcp-ack) != 0'

Method 3: Check Firewall Logs

sudo ufw status verbose
sudo tail -f /var/log/ufw.log

Was this article helpful?