To make sure fail2ban breaks the connection, you need to put the fail2ban rules BEFORE any "ESTABLISHED,RELATED" rule. Then it will simply drop the packets regardless of if the connection is in the firewall's state table or not.
smime.p7s
Description: S/MIME Cryptographic Signature