<div dir="ltr">If you are trying to reject an IP address to connect to asterisk, there is no need to run iptables.<br>Each SIP definition in sip.conf can have:<br>deny=<a href="http://0.0.0.0/0.0.0.0">0.0.0.0/0.0.0.0</a><br>
permit=<a href="http://192.168.135.1/255.255.255.0">192.168.135.1/255.255.255.0</a><br><br>just set these values and it wont accept anything from that IP.<br><br><br><div class="gmail_quote">On Mon, Jul 7, 2008 at 7:37 PM, Dovid B <<a href="mailto:asteriskusers@dovid.net">asteriskusers@dovid.net</a>> wrote:<br>
<blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"><div class="Ih2E3d"><br>
----- Original Message -----<br>
From: "spectro" <<a href="mailto:spectro@gmail.com">spectro@gmail.com</a>><br>
To: "Asterisk Users Mailing List - Non-Commercial Discussion"<br>
</div><div class="Ih2E3d"><<a href="mailto:asterisk-users@lists.digium.com">asterisk-users@lists.digium.com</a>><br>
Sent: Tuesday, July 01, 2008 8:02 PM<br>
Subject: Re: [asterisk-users] sip extension compromised,need help blocking<br>
brute force attempts<br>
<br>
<br>
</div><div><div></div><div class="Wj3C7c">> On Tue, Jul 1, 2008 at 11:19 AM, Tzafrir Cohen <<a href="mailto:tzafrir.cohen@xorcom.com">tzafrir.cohen@xorcom.com</a>><br>
> wrote:<br>
>><br>
>> Fix your logger.conf, then.<br>
>><br>
>> --<br>
>> Tzafrir Cohen<br>
><br>
> What am I missing?<br>
><br>
><br>
> [root@asterisk1 ~]# cat /etc/asterisk/logger.conf<br>
> ;<br>
> ; Logging Configuration<br>
> ;<br>
> ; In this file, you configure logging to files or to<br>
> ; the syslog system.<br>
> ;<br>
> ; For each file, specify what to log.<br>
> ;<br>
> ; For console logging, you set options at start of<br>
> ; Asterisk with -v for verbose and -d for debug<br>
> ; See 'asterisk -h' for more information.<br>
> ;<br>
> ; Directory for log files is configures in asterisk.conf<br>
> ; option astlogdir<br>
> ;<br>
> [logfiles]<br>
> ;<br>
> ; Format is "filename" and then "levels" of debugging to be included:<br>
> ; debug<br>
> ; notice<br>
> ; warning<br>
> ; error<br>
> ; verbose<br>
> ;<br>
> ; Special filename "console" represents the system console<br>
> ;<br>
> ;debug => debug<br>
> ;console => notice,warning,error<br>
> ;console => notice,warning,error,debug<br>
> ;messages => notice,warning,error<br>
> full => notice,warning,error,debug,verbose<br>
><br>
> ;syslog keyword : This special keyword logs to syslog facility<br>
> ;<br>
> ;syslog.local0 => notice,warning,error<br>
> ;<br>
> [root@asterisk1 ~]#<br>
><br>
</div></div>The script seems to run off the messages log. Uncomment the messages line<br>
and the reload the logger in asterisk (logger reload from the CLI).<br>
<div><div></div><div class="Wj3C7c"><br>
<br>
<br>
_______________________________________________<br>
-- Bandwidth and Colocation Provided by <a href="http://www.api-digital.com" target="_blank">http://www.api-digital.com</a> --<br>
<br>
AstriCon 2008 - September 22 - 25 Phoenix, Arizona<br>
Register Now: <a href="http://www.astricon.net" target="_blank">http://www.astricon.net</a><br>
<br>
asterisk-users mailing list<br>
To UNSUBSCRIBE or update options visit:<br>
<a href="http://lists.digium.com/mailman/listinfo/asterisk-users" target="_blank">http://lists.digium.com/mailman/listinfo/asterisk-users</a><br>
</div></div></blockquote></div><br></div>