# Can I simply deny access to an IP address (s)

**URL:** <https://community.learnlinux.tv/t/can-i-simply-deny-access-to-an-ip-address-s/1791>\
**Category:** Linux Security\
**Created:** [August 7, 2022, 1:04pm UTC](https://community.learnlinux.tv/t/can-i-simply-deny-access-to-an-ip-address-s/1791 "2022-08-07T13:04:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AnOldSlowHorse](https://community.learnlinux.tv/letter_avatar_proxy/v4/letter/a/87869e/32.png) [@AnOldSlowHorse](https://community.learnlinux.tv/u/AnOldSlowHorse)\
**Post date:** [August 7, 2022, 1:04pm UTC](https://community.learnlinux.tv/t/can-i-simply-deny-access-to-an-ip-address-s/1791/1 "2022-08-07T13:04:04Z")

</div>

have Apache2 installed  
I used the video from Jay on YouTube to set up fail2ban, and all appears to be working  
Could anyone tell me If:  
Can I simply deny access to an IP address (s) from my visting my server permanently ?

I’m just forearming myself , just incase I have to do more.  
I’m just monitoring my access log for now.  
Please see attached screenshots

 ![Screenshot 2022-08-07 at 13.41.11](https://community.learnlinux.tv/uploads/default/original/1X/5f98476030d2c6772139fa974b331a0c2515a8fa.jpeg)

Thank you in advance for your help

 ![Screenshot 2022-08-07 at 13.41.54](https://community.learnlinux.tv/uploads/default/original/1X/9f997c6e37ece3ea8ec0795dfa54333d47a4158d.jpeg)

---

<div class="post-metadata">

**Author:** ![ThatGuyB](https://community.learnlinux.tv/user_avatar/community.learnlinux.tv/thatguyb/32/784_2.png) [@ThatGuyB](https://community.learnlinux.tv/u/ThatGuyB)\
**Post date:** [August 7, 2022, 2:04pm UTC](https://community.learnlinux.tv/t/can-i-simply-deny-access-to-an-ip-address-s/1791/2 "2022-08-07T14:04:10Z")

</div>

If you want to drop an IP address permanently, just do it via iptables.

```auto
iptables -I INPUT -s 66.249.64.223 -j DROP

```

This drops connection from that IP coming in your server on any ports. You can use -p tcp --dport 80 or -p udp --dport 53 to block access only to specific ports on your server coming from that IP. Or you can skip the -s to block access from anywhere coming on those ports, but if you don’t mention sources, you risk locking yourself out.

---

<div class="post-metadata">

**Author:** ![AnOldSlowHorse](https://community.learnlinux.tv/letter_avatar_proxy/v4/letter/a/87869e/32.png) [@AnOldSlowHorse](https://community.learnlinux.tv/u/AnOldSlowHorse)\
**Post date:** [August 7, 2022, 2:18pm UTC](https://community.learnlinux.tv/t/can-i-simply-deny-access-to-an-ip-address-s/1791/3 "2022-08-07T14:18:48Z")

</div>

wow,  
Thanks  
I will have to try and digest your reply
