beautypg.com

Fail2ban, Change password, Table 16: fail2ban settings – Grandstream UCM6510 User Manual User Manual

Page 61

background image

Firmware Version 1.0.2.5

UCM6510 IP PBX User Manual

Page 60 of 313

FAIL2BAN

Fail2Ban feature on the UCM6510 provides intrusion detection and prevention for authentication errors in

SIP REGISTER, INVITE and SUBSCRIBE. Once the entry is detected within "Max Retry Duration", the

UCM6510 will take action to forbid the host for certain period as defined in "Banned Duration". This feature

helps prevent SIP brute force attacks to the PBX system.

Table 16: Fail2Ban Settings

Global Settings

Enable Fail2Ban

Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable

Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP

authentication on the UCM6510.

Banned Duration

Configure the duration (in seconds) for the detected host to be banned. The default

setting is 300. If set to -1, the host will be always banned.

Max Retry Duration

Within this duration (in seconds), if a host exceeds the max times of retry as

defined in "MaxRetry", the host will be banned. The default setting is 5.

MaxRetry

Configure the number of authentication failures during "Max Retry Duration" before

the host is banned. The default setting is 10.

Fail2Ban Whitelist

Configure IP address, CIDR mask or DNS host in the whiltelist. Fail2Ban will not

ban the host with matching address in this list. Up to 5 addresses can be added

into the list.

Local Settings

Asterisk Service

Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make

sure both "Enable Fail2Ban" and "Asterisk Service" are turned on in order to use

Fail2Ban for SIP authentication on the UCM6510.

Protocol

Configure the listening port number for the service. Currently only 5060 (for UDP)

is supported.

MaxRetry

Configure the number of authentication failures during "Max Retry Duration" before

the host is banned. The default setting is 10. Please make sure this option is

properly configured as it will override the "MaxRetry" value under "Global Settings".

CHANGE PASSWORD

After logging in the web GUI for the first time, it is highly recommended for users to change the default

password "admin" to a more complicated password for security purpose. Follow the steps below to change

the web GUI access password.

1. Go to web GUI->Settings->Change Password page.