authfail is a tool for adding IP addresses to an ACL when entities from those addresses attempt to log into a system, but cause authentication failures in auth.log. It reads data from auth.log in real time and adds the IP into netfilter with a DROP/REJECT policy.
c31e42c5443566243213fffc80da1bff4bc9d2cdb9effe26767b66b53f9679c2