Ssh Access; Table 15: Fail2Ban Settings - Grandstream Networks UCM6202 User Manual

Ucm6200 series ip pbx
Hide thumbs Also See for UCM6202:
Table of Contents

Advertisement

Global Settings
Enable Fail2Ban
Banned Duration
Max Retry Duration
MaxRetry
Fail2Ban Whitelist
Local Settings
Asterisk Service
Protocol
MaxRetry
Login Attack Defense
Listening Port
Number
MaxRetry
Blacklist
Black List

SSH Access

SSH switch now is available via Web GUI and LCD. User can enable or disable SSH access directly from Web
GUI or LCD screen. For web SSH access, please log in UCM6200 web interface and go to Web GUISystem
SettingsSecurity SettingsSSH Access. By default, SSH access is disabled for security concerns. It is
highly recommended to only enable SSH access for debugging purpose.

Table 15: Fail2Ban Settings

Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable
Fail2Ban" and "Asterisk Service" are turned on to use Fail2Ban for SIP
authentication on the UCM6200.
Configure the duration (in seconds) for the detected host to be banned. The default
setting is 300. If set to -1, the host will be always banned.
Within this duration (in seconds), if a host exceeds the max times of retry as
defined in "MaxRetry", the host will be banned. The default setting is 5.
Configure the number of authentication failures during "Max Retry Duration" before
the host is banned. The default setting is 10.
Configure IP address, CIDR mask or DNS host in the whitelist. Fail2Ban will not
ban the host with matching address in this list. Up to 5 addresses can be added
into the list.
Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make
sure both "Enable Fail2Ban" and "Asterisk Service" are turned on to use Fail2Ban
for SIP authentication on the UCM6200.
Configure the listening port number for the service. Currently only 5060 (for UDP)
is supported.
Configure the number of authentication failures during "Max Retry Duration" before
the host is banned. The default setting is 10. Please make sure this option is
properly configured as it will override the "MaxRetry" value under "Global Settings".
Enables defense against excessive login attacks to the UCM's web GUI.
The default setting is disabled.
This is the Web GUI listening port number which is configured under System
SettingsHTTP ServerPort. The default is 8089.
When the number of failed login attempts from an IP address exceeds the
MaxRetry number, that IP address will be banned from accessing the Web GUI.
Users will be able to view the IPs that have been blocked by UCM.
UCM6200 Series User Manual
P a g e
|
63

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ucm6204Ucm6208

Table of Contents