# Fail2Ban filter for SIP scanners / endpoint-enumeration tools (Asterisk 16–22). # # Aggressively bans probing that hits "No matching endpoint found" (scanners # spraying random extensions) plus known scanner User-Agents. Matches the real # Asterisk 22 res_pjsip format: # # [2026-07-13 09:53:01] NOTICE[123] res_pjsip/pjsip_distributor.c: # Request 'REGISTER' from '...' failed for '203.0.113.9:5089' # (callid: ...) - No matching endpoint found # # NOTE: the previous version anchored on "No matching endpoint found for '...' # from ''", but Asterisk 22 puts the host in "failed for ''" BEFORE # the reason — so it matched nothing. This keys on the correct position. [INCLUDES] before = common.conf [Definition] _daemon = asterisk # fail2ban strips the [date] (see datepattern) before matching — do not anchor on it. failregex = res_pjsip/pjsip_distributor\.c:\s*Request '\w+' from '.*' failed for ':\d+'.* - No matching endpoint found\s*$ Request from '"?(friendly-scanner|sipvicious|sundayddr|sip-scan|sipcli|VaxSIPUserAgent|pplsip)"?.*' failed for ':\d+' ignoreregex = datepattern = ^\[%%Y-%%m-%%d %%H:%%M:%%S\]