# Fail2Ban filter for Asterisk Manager Interface (AMI) brute-force # Catches failed AMI login attempts [INCLUDES] before = common.conf [Definition] _daemon = asterisk failregex = ^.*NOTICE.* .*: failed to authenticate.*$ ^.*SECURITY.* .*: SecurityEvent="FailedACL".*Service="AMI".*RemoteAddress="IPV[46]/(udp|tcp)//\d+".*$ ^.*NOTICE.* .*manager.c: tried to authenticate with nonexistent user.*$ ^.*NOTICE.* .*manager.c:.*failed challenge from.*.*$ ignoreregex =