beautypg.com

Fail2ban, Table 19: fail2ban settings, Figure 35: configure dynamic defense – Grandstream UCM6100 User Manual for 1.0.9.25 User Manual

Page 71

background image

Firmware Version 1.0.9.25

UCM6100 Series IP PBX User Manual

Page 70 of 303

• If a host at IP address 192.168.40.7 initiates more than 20 TCP connections to the UCM6100 within 1

minute, it will be added into UCM6100 blacklist.

• This host 192.168.40.7 will be blocked by the UCM6100 for 300 seconds.
• Since IP address 192.168.40.5 is in whitelist, if the host at IP address 192.168.40.5 initiates more than

20 TCP connections to the UCM6100 within 1 minute, it will not be added into UCM6100 blacklist. It

can still establish TCP connection with the UCM6100.

Figure 35: Configure Dynamic Defense

FAIL2BAN

Fail2Ban feature on the UCM6100 provides intrusion detection and prevention for authentication errors in

SIP REGISTER, INVITE and SUBSCRIBE. Once the entry is detected within "Max Retry Duration", the

UCM6100 will take action to forbid the host for certain period as defined in "Banned Duration". This feature

helps prevent SIP brute force attacks to the PBX system.

Table 19: Fail2Ban Settings

Global Settings

Enable Fail2Ban

Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable

Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP

authentication on the UCM6100.

Banned Duration

Configure the duration (in seconds) for the detected host to be banned. The

default setting is 300. If set to -1, the host will be always banned.

Max Retry Duration

Within this duration (in seconds), if a host exceeds the max times of retry as

defined in "MaxRetry", the host will be banned. The default setting is 5.

This manual is related to the following products: