Ssh Access; Table 17: Fail2Ban Settings - Grandstream Networks UCM6510 User Manual

Ip pbx
Hide thumbs Also See for UCM6510:
Table of Contents

Advertisement

Global Settings
Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable
Enable Fail2Ban
Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP
authentication on the UCM6510.
Configure the duration (in seconds) for the detected host to be banned. The default
Banned Duration
setting is 300. If set to -1, the host will be always banned.
Within this duration (in seconds), if a host exceeds the max times of retry as defined
Max Retry Duration
in "MaxRetry", the host will be banned. The default setting is 5.
Configure the number of authentication failures during "Max Retry Duration" before
MaxRetry
the host is banned. The default setting is 10.
Configure IP address, CIDR mask or DNS host in the whitelist. Fail2Ban will not ban
Fail2Ban Whitelist
the host with matching address in this list. Up to 5 addresses can be added into the
list.
Local Settings
Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make
Asterisk Service
sure both "Enable Fail2Ban" and "Asterisk Service" are turned on in order to use
Fail2Ban for SIP authentication on the UCM6510.
Configure the listening port number for the service. Currently only 5060 (for UDP)
Protocol
is supported.
Configure the number of authentication failures during "Max Retry Duration" before
MaxRetry
the host is banned. The default setting is 10. Please make sure this option is
properly configured as it will override the "MaxRetry" value under "Global Settings".
Enables defense against excessive login attacks to the UCM's web GUI.
Login Attack Defense
The default setting is disabled.
Listening Port
This is the Web GUI listening port number which is configured under System
Number
SettingsHTTP ServerPort. The default is 8089.
When the number of failed login attempts from an IP address exceeds the MaxRetry
MaxRetry
number, that IP address will be banned from accessing the UCM Web UI.
Blacklist
Blacklist
Users will be able to view the IPs that have been blocked by UCM.

SSH Access

SSH switch now is available via Web GUI and LCD. User can enable or disable SSH access directly from
Web GUI or LCD screen. For web SSH access, please log in UCM6510 web interface and go to System
SettingsSecurity SettingsSSH Access. By default, SSH access is disabled for security concerns. It
is highly recommended to only enable SSH access for debugging purpose.

Table 17: Fail2Ban Settings

UCM6510 IP PBX User Manual
P a g e
|
75

Advertisement

Table of Contents
loading

Table of Contents