[CentOS] Blocking attacks from a range of IP addresses

Thu Jan 9 00:37:15 UTC 2020
H <agents at meddatainc.com>

I am being attacked by an entire subnet where the first two parts of the IP address remain identical but the last two parts vary sufficiently that it is not caught by fail2ban since the attempts do not meet the cut-off of a certain number of attempts within the given time.

Has anyone created a fail2ban filter for this type of attack? As of right now, I have manually banned a range of IP addresses but would like to automate it for the future.