# ============================================================================= # SIP scanner detection (aggressive: ban after 2 hits for 24h). # Installed into /etc/fail2ban/jail.d/ by `php artisan pbx:deploy`. # # This drop-in exists to OVERRIDE any drifted `backend = systemd` in # jail.local. Asterisk on these boxes logs to FILES (/var/log/asterisk/*), # not the journal — a systemd backend makes the jail see nothing and never # ban. `backend = auto` + explicit file logpaths guarantees it reads the logs. # # Ban via nftables (inherited from [DEFAULT] banaction = nftables-multiport). # ============================================================================= # AGGRESSIVE tier: "No matching endpoint found" = probing a non-existent # extension. A legitimate phone NEVER does this (it knows its real extension), # so this is safe to ban hard regardless of a changing office IP — no whitelist # reliance needed. 2 strikes, banned a week. [asterisk-scanner] enabled = true port = 5060,5061 protocol = udp,tcp filter = asterisk-scanner backend = auto logpath = /var/log/asterisk/messages /var/log/asterisk/full maxretry = 2 findtime = 3600 bantime = 604800