# ============================================================================= # PBX Fail2Ban Jail Configuration # Copy to /etc/fail2ban/jail.local # ============================================================================= [DEFAULT] # Ban for 1 hour by default bantime = 3600 # Detection window: 10 minutes findtime = 600 # Ban after 5 failures maxretry = 5 # Use nftables for banning (modern Linux) banaction = nftables-multiport banaction_allports = nftables-allports # Ignore private networks and localhost ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 # ============================================================================= # SSH — protect against brute-force # ============================================================================= [sshd] enabled = true port = 2205 filter = sshd logpath = /var/log/auth.log maxretry = 3 bantime = 86400 findtime = 600 # ============================================================================= # Asterisk PJSIP — SIP registration brute-force and scanner protection # ============================================================================= [asterisk-pjsip] enabled = true port = 5060,5061 protocol = udp,tcp filter = asterisk-pjsip logpath = /var/log/asterisk/messages maxretry = 5 bantime = 3600 findtime = 600 # ============================================================================= # Asterisk AMI — Manager Interface brute-force # ============================================================================= [asterisk-ami] enabled = true port = 5038 filter = asterisk-ami logpath = /var/log/asterisk/messages maxretry = 3 bantime = 86400 findtime = 300 # ============================================================================= # Asterisk Security — catches all security events from Asterisk security log # ============================================================================= [asterisk-security] enabled = true port = 5060,5061 protocol = udp,tcp filter = asterisk-security logpath = /var/log/asterisk/security maxretry = 3 bantime = 7200 findtime = 600 # ============================================================================= # Web GUI login brute-force protection is provided by the [pbx-weblogin] jail # in jail.d/pbx-weblogin.conf, which watches Laravel's dedicated auth-failure # log (real failures only). The old access-log-based [pbx-web] jail was removed # because it banned successful logins too (Laravel returns HTTP 302 on success # AND failure, so the web-server status code can't tell them apart). # ============================================================================= # ============================================================================= # SIP Scanner — aggressive ban for known SIP scanning tools # Bans for 24 hours after just 2 attempts # ============================================================================= [asterisk-scanner] enabled = true port = 5060,5061 protocol = udp,tcp filter = asterisk-scanner logpath = /var/log/asterisk/messages maxretry = 2 bantime = 86400 findtime = 3600 # ============================================================================= # Recidive — ban repeat offenders for 1 week # Watches the fail2ban log itself for IPs that keep getting banned # ============================================================================= [recidive] enabled = true filter = recidive logpath = /var/log/fail2ban.log banaction = nftables-allports maxretry = 3 bantime = 604800 findtime = 86400