# Fail2Ban filter for Asterisk Security log # Catches all security events from /var/log/asterisk/security [INCLUDES] before = common.conf [Definition] _daemon = asterisk failregex = ^.*SecurityEvent="FailedACL".*RemoteAddress="IPV[46]/(udp|tcp)//\d+".*$ ^.*SecurityEvent="InvalidAccountID".*RemoteAddress="IPV[46]/(udp|tcp)//\d+".*$ ^.*SecurityEvent="ChallengeResponseFailed".*RemoteAddress="IPV[46]/(udp|tcp)//\d+".*$ ^.*SecurityEvent="InvalidPassword".*RemoteAddress="IPV[46]/(udp|tcp)//\d+".*$ ^.*SecurityEvent="UnexpectedAddress".*RemoteAddress="IPV[46]/(udp|tcp)//\d+".*$ ^.*SecurityEvent="RequestBadFormat".*RemoteAddress="IPV[46]/(udp|tcp)//\d+".*$ ignoreregex =