Fail2Ban; Table 13: Fail2Ban Settings; Figure 16: Configure Dynamic Defense - Grandstream Networks UCM6510 IP PBX User Manual

Ip pbx
Hide thumbs Also See for UCM6510 IP PBX:
Table of Contents

Advertisement

If a host at IP address 192.168.40.7 initiates more than 20 TCP connections to the UCM6510 within 1
minute, it will be added into UCM6510 blacklist.
This host 192.168.40.7 will be blocked by the UCM6510 for 300 seconds.
Since IP address 192.168.40.5 is in whitelist, if the host at IP address 192.168.40.5 initiates more
than 20 TCP connections to the UCM6510 within 1 minute, it will not be added into UCM6510
blacklist. It can still establish TCP connection with the UCM6510.

FAIL2BAN

Fail2Ban feature on the UCM6510 provides intrusion detection and prevention for authentication errors in
SIP REGISTER, INVITE and SUBSCRIBE. Once the entry is detected within "Max Retry Duration", the
UCM6510 will take action to forbid the host for certain period as defined in "Banned Duration". This
feature helps prevent SIP brute force attacks to the PBX system.
Global Settings
Enable Fail2Ban
Banned Duration
Max Retry Duration
Firmware Version 1.0.0.25
VoIPon www.voipon.co.uk sales@voipon.co.uk Tel: +44 (0)1245 808195 Fax: +44 (0)1245 808299

Figure 16: Configure Dynamic Defense

Table 13: Fail2Ban Settings

Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable
Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP
authentication on the UCM6510.
Configure the duration (in seconds) for the detected host to be banned. The
default setting is 300. If set to -1, the host will be always banned.
Within this duration (in seconds), if a host exceeds the max times of retry as
defined in "MaxRetry", the host will be banned. The default setting is 5.
UCM6510 IP PBX User Manual
Page 44 of 229

Advertisement

Table of Contents
loading

Table of Contents