<div dir="ltr"><div><div><div>Our academic rich - resource poor - University does not have an IDS on networks per say.<br><br></div>Our Shibboleth is running with the Apache/Tomcat on RHEL - stack.<br><br></div>We are thinking of placing Fail2Ban to send out alerts on events in the Apache logs -- we are less worried about the Shibboleth, than perhaps forĀ  blocking the suspect IP to protect other systems (there is no budget for IDS).<br><br></div>What are you thoughts -- based on above parameters? Are there alternatives to Fal2Ban -- that come at same price (i.e. free)?<br><div><div><div><br><br></div></div></div></div>