Hat man schon lokale iptables Regeln und fail2ban logged Fehler geht das über ip route
# vi /etc/fail2ban/action.d/route.conf
[Definition] actionban = ip route add unreachable <ip> actionunban = ip route del unreachable <ip>
# vi /etc/fail2ban/jail.conf
banaction = route
# vi /etc/init.d/fail2ban restart