maxretry / findtime — if these failed attempts happen within this time window, the IP gets banned. Setting maxretry too high lets slow attacks through; setting it too low can ban someone who just mistyped a password.
bantime — how long the ban lasts. -1 means permanent until removed by hand with fail2ban-client.
After saving the file: sudo systemctl restart fail2ban, and confirm it loaded with sudo fail2ban-client status [jail].
FerroSentry installs and configures fail2ban on its own
Already-calibrated presets, no need to hand-pick maxretry and bantime — and watched continuously afterward.