Fail2Ban; Change Password; Table 13: Fail2Ban Settings - Grandstream Networks UCM6510 IP PBX User Manual

Hide thumbs Also See for UCM6510 IP PBX:
Table of Contents

Advertisement

FAIL2BAN

Fail2Ban feature on the UCM6510 provides intrusion detection and prevention for authentication errors in
SIP REGISTER, INVITE and SUBSCRIBE. Once the entry is detected within "Max Retry Duration", the
UCM6510 will take action to forbid the host for certain period as defined in "Banned Duration". This feature
helps prevent SIP brute force attacks to the PBX system.
Global Settings
Enable Fail2Ban
Banned Duration
Max Retry Duration
MaxRetry
Fail2Ban Whitelist
Local Settings
Asterisk Service
Port
MaxRetry

CHANGE PASSWORD

After logging in the web GUI for the first time, it is highly recommended for users to change the default
password "admin" to a more complicated password for security purpose. Follow the steps below to change
the web GUI access password.
1. Go to web GUI->Settings->Change Password page.
Firmware Version 1.0.1.12

Table 13: Fail2Ban Settings

Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable
Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP
authentication on the UCM6510.
Configure the duration (in seconds) for the detected host to be banned. The default
setting is 300. If set to -1, the host will be always banned.
Within this duration (in seconds), if a host exceeds the max times of retry as
defined in "MaxRetry", the host will be banned. The default setting is 5.
Configure the number of authentication failures during "Max Retry Duration" before
the host is banned. The default setting is 10.
Configure IP address, CIDR mask or DNS host in the whiltelist. Fail2Ban will not
ban the host with matching address in this list. Up to 5 addresses can be added
into the list.
Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make
sure both "Enable Fail2Ban" and "Asterisk Service" are turned on in order to use
Fail2Ban for SIP authentication on the UCM6510.
Configure the listening port number for the service. Currently only 5060 (for UDP)
is supported.
Configure the number of authentication failures during "Max Retry Duration" before
the host is banned. The default setting is 10. Please make sure this option is
properly configured as it will override the "MaxRetry" value under "Global Settings".
UCM6510 IP PBX User Manual
Page 50 of 277

Advertisement

Table of Contents
loading

Table of Contents