# ============================================================================= # Core Asterisk brute-force jails: PJSIP registration + AMI. # Installed into /etc/fail2ban/jail.d/ by `php artisan pbx:deploy`. # # These drop-ins OVERRIDE any drifted `backend = systemd` in jail.local. # Asterisk logs to FILES here, not the journal, so a systemd backend makes # these jails blind. `backend = auto` + explicit file logpaths fixes that. # ============================================================================= # LENIENT tier: "Failed to authenticate" on an EXISTING extension (wrong # password). This is the only case that could catch a mis-provisioned legit # phone, so allow more attempts before banning; whitelisted ranges (ignoreip) # are exempt. A correctly provisioned phone never trips this. [asterisk-pjsip] enabled = true port = 5060,5061 protocol = udp,tcp filter = asterisk-pjsip backend = auto logpath = /var/log/asterisk/messages /var/log/asterisk/full maxretry = 5 findtime = 600 bantime = 3600 [asterisk-ami] enabled = true port = 5038 filter = asterisk-ami backend = auto logpath = /var/log/asterisk/messages /var/log/asterisk/full maxretry = 3 findtime = 300 bantime = 86400