[asterisk-users] stopping unwanted attempts

Eric Wieling EWieling at nyigc.com
Sun Jan 19 14:01:14 CST 2014


We don't do residential service and require the few off-net customers to have a static IP.   This makes using whitelists practical.    That won't work for most people though.

-----Original Message-----
From: asterisk-users-bounces at lists.digium.com [mailto:asterisk-users-bounces at lists.digium.com] On Behalf Of Andrew Colin
Sent: Sunday, January 19, 2014 2:39 PM
To: Asterisk Users Mailing List - Non-Commercial Discussion
Subject: Re: [asterisk-users] stopping unwanted attempts

Geoip works well to block all countries except your own


Regards
Andrew Colin-mobile
Vsave(PTY)Ltd



-------- Original message --------
From: Eric Wieling
Date:19/01/2014 8:40 PM (GMT+02:00)
To: Asterisk Users Mailing List - Non-Commercial Discussion
Subject: Re: [asterisk-users] stopping unwanted attempts 


It is far worse when you have multiple phones behind the same public address (i.e. NAT).    If any one of the phones has a bad password and the IP gets blocked by fail2ban, then all phones at that site would be blocked. 

-----Original Message-----
From: asterisk-users-bounces at lists.digium.com [mailto:asterisk-users-bounces at lists.digium.com] On Behalf Of Chris Bagnall
Sent: Sunday, January 19, 2014 10:40 AM
To: asterisk-users at lists.digium.com
Subject: Re: [asterisk-users] stopping unwanted attempts

On 19/1/14 2:57 pm, Ron Wheeler wrote:
> fail2ban is so easy to set up, there is no reason not to set it up.

One of the dangers with fail2ban - at least in its default configuration
- is that a legitimate SIP phone with an incorrect password can quite easily send dozens of registration attempts in a couple of minutes, thus blocking that IP.


--
_____________________________________________________________________
-- Bandwidth and Colocation Provided by http://www.api-digital.com -- New to Asterisk? Join us for a live introductory webinar every Thurs:
               http://www.asterisk.org/hello

asterisk-users mailing list
To UNSUBSCRIBE or update options visit:
   http://lists.digium.com/mailman/listinfo/asterisk-users



More information about the asterisk-users mailing list