I would recommend sshguard [1] as a fail2ban replacement. It does much of what fail2ban used to do out of the box and has supported ipv6 for a long, long time.
It is packaged in debian, ubuntu and probably other major distros these days.
It is packaged in debian, ubuntu and probably other major distros these days.
In the many, many, many months I've had my internet-facing IPv6-enabled SSH servers online, I've only received one bogus SSH connection attempt from an IPv6 address at the University of Michigan.
Interesting though is that covering the entire IPv6 space is a much larger task. That should hold down the volume of random attempts for a while, just by dilution effect.
I do that when I can, but sometimes it's not possible.
Also, fail2ban works for other things besides ssh, which I need.