<br><br><div class="gmail_quote">On Sat, Dec 25, 2010 at 7:41 PM, dave george <span dir="ltr">&lt;<a href="mailto:dgeorge@teletoneinc.com">dgeorge@teletoneinc.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">
Yes we have that set in logger.conf.<br>
<div><div></div><div class="h5"><br>
-----Original Message-----<br>
From: <a href="mailto:asterisk-users-bounces@lists.digium.com">asterisk-users-bounces@lists.digium.com</a><br>
[mailto:<a href="mailto:asterisk-users-bounces@lists.digium.com">asterisk-users-bounces@lists.digium.com</a>] On Behalf Of Nick Ustinov<br>
Sent: Saturday, December 25, 2010 6:25 PM<br>
To: Asterisk Users Mailing List - Non-Commercial Discussion<br>
Subject: Re: [asterisk-users] sip attack.. fail2ban not stopping attack<br>
<br>
Make sure you have<br>
<br>
dateformat=%F %T<br>
<br>
in logger.conf<br>
<br>
<br>
<br>
On Sun, Dec 26, 2010 at 1:04 AM, Dave George &lt;<a href="mailto:dgeorge@teletoneinc.com">dgeorge@teletoneinc.com</a>&gt;<br>
wrote:<br>
&gt; My server is being attached all day and fail2ban is not stopping the<br>
&gt; attack. I updated stamstamp to match fail2ban requirements.<br>
&gt;<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot; &#39;<br>
&gt; failed for &#39;38.108.40.94&#39; - No matching peer found<br>
&gt; [2010-12-25 18:54:34] NOTICE[15415]: chan_sip.c:21830<br>
&gt; handle_request_register: Registration from &#39;&quot;7002&quot;<br>
&gt; Dave<br>
&gt;<br>
&gt;<br></div></div></blockquote><div><br>If all else fails, check your /var/log/fail2ban log file. Any error messages there?<br> A typo in the file name of the log file to check; a jail that is set up but not<br>turned on; double check your set up. Use iptables -L -n to check<br>
that fail2ban is properly setting up a chain to block ip&#39;s. Is the<br>fail2ban service even running?<br><br>murf<br> <br></div></div><div id="WISESTAMP_SIG_9031"><span style="font-size: 13.3px; font-family: Verdana,Arial,Helvetica,sans-serif;"><img src="http://s.wisestamp.com/pixel.png?p=mozilla&amp;v=2.0.4&amp;t=1293341472136&amp;u=5848228&amp;e=7797" height="1" width="1"></span></div>