No, no… you must be right, you have more experience with fail2ban than me.
Certainly the proxy chain Squid+privoxy is a better way to go…
I’m a little surprise with too few answers about this subjet…
To save bandwith and better filtering are good things for a Firewall distribution…