Ssh Access; Table 17: Fail2Ban Settings - Grandstream Networks UCM6100 Series User Manual

Ip pbx
Hide thumbs Also See for UCM6100 Series:
Table of Contents

Advertisement

Global Settings
Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable
Enable Fail2Ban
Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP
authentication on the UCM6100.
Configure the duration (in seconds) for the detected host to be banned. The default
Banned Duration
setting is 300. If set to 0, the host will be always banned.
Within this duration (in seconds), if a host exceeds the max times of retry as
Max Retry Duration
defined in "MaxRetry", the host will be banned. The default setting is 5.
Configure the number of authentication failures during "Max Retry Duration" before
MaxRetry
the host is banned. The default setting is 10.
Configure IP address, CIDR mask or DNS host in the whitelist. Fail2Ban will not
Fail2Ban Whitelist
ban the host with matching address in this list. Up to 5 addresses can be added
into the list.
Local Settings
Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make
Asterisk Service
sure both "Enable Fail2Ban" and "Asterisk Service" are turned on in order to use
Fail2Ban for SIP authentication on the UCM6100.
Configure the listening port number for the service. Currently only 5060 (for UDP)
Protocol
is supported.
Configure the number of authentication failures during "Max Retry Duration" before
MaxRetry
the host is banned. The default setting is 10. Please make sure this option is
properly configured as it will override the "MaxRetry" value under "Global Settings".
Enables defense against excessive login attacks to the UCM's web GUI.
Login Attack Defense
The default setting is disabled.
Listening Port
This is the Web GUI listening port number which is configured under System
Number
SettingsHTTP ServerPort. The default is 8089.
When the number of failed login attempts from an IP address exceeds the
MaxRetry
MaxRetry number, that IP address will be banned from accessing the UCM Web
UI.
Blacklist
Blacklist
Users will be able to view the IPs that have been blocked by UCM.

SSH Access

SSH switch now is available via Web GUI and LCD. User can enable or disable SSH access directly from
Web GUI or LCD screen. For web SSH access, please log in UCM 6100 web interface and go to System
SettingsSecurity SettingsSSH Access. By default, SSH access is disabled for security concerns. It
is highly recommended to only enable SSH access for debugging purpose.

Table 17: Fail2Ban Settings

UCM6100 Series User Manual
P a g e
74
|

Advertisement

Table of Contents
loading

Table of Contents