Fail2Ban; Table 18: Fail2Ban Settings; Figure 38: Configure Dynamic Defense - Grandstream Networks UCM6202 User Manual

Ucm6200 series ip pbx
Hide thumbs Also See for UCM6202:
Table of Contents

Advertisement

Fail2ban

Fail2Ban feature on the UCM6200 provides intrusion detection and prevention for authentication errors in
SIP REGISTER, INVITE and SUBSCRIBE. Once the entry is detected within "Max Retry Duration", the
UCM6200 will take action to forbid the host for certain period as defined in "Banned Duration". This feature
helps prevent SIP brute force attacks to the PBX system.
Global Settings
Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable
Enable Fail2Ban
Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP
authentication on the UCM6200.
Configure the duration (in seconds) for the detected host to be banned. The default
Banned Duration
setting is 300. If set to -1, the host will be always banned.
Within this duration (in seconds), if a host exceeds the max times of retry as
Max Retry Duration
defined in "MaxRetry", the host will be banned. The default setting is 5.
Configure the number of authentication failures during "Max Retry Duration" before
MaxRetry
the host is banned. The default setting is 10.
Configure IP address, CIDR mask or DNS host in the whitelist. Fail2Ban will not
Fail2Ban Whitelist
ban the host with matching address in this list. Up to 5 addresses can be added
into the list.
Local Settings
Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make
Asterisk Service
sure both "Enable Fail2Ban" and "Asterisk Service" are turned on in order to use
Fail2Ban for SIP authentication on the UCM6200.

Figure 38: Configure Dynamic Defense

Table 18: Fail2Ban Settings

UMC6200 Series User Manual
P a g e
|
63

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

This manual is also suitable for:

Ucm6204Ucm6208

Table of Contents