# ============================================================================= # SIP scanner/brute-force detection (sipvicious, friendly-scanner, etc.). # Installed into /etc/fail2ban/jail.d/ by `php artisan pbx:deploy`. # # Uses nftables (inherited from [DEFAULT] banaction = nftables-multiport). # NOTE: do NOT use `action = ipset-pbx` — ipset has no effect on nftables-only # PBXs (the set is never referenced in the nftables ruleset). Port-based # nftables ban via the default action is correct. # ============================================================================= [asterisk-sipvicious] enabled = true port = 5060,5061 filter = asterisk-sipvicious logpath = /var/log/asterisk/full /var/log/asterisk/messages backend = auto findtime = 300 maxretry = 1 bantime = 604800