enable fail2ban

Status
Not open for further replies.

mrjoli021

Member
Jul 20, 2017
133
2
18
47
I have a fusionnbx system connected to an SBC for public registrations. I am now getting pounded by people trying to hack my system. How can I enable fail2ban to block these attempts? I am using the default fail2ban settings and apparently they are not blocking anything. How can I tweak the rules to start blocking bad register attempts?

root@fusionpbx:~# iptables -n -L
Chain INPUT (policy DROP)
target prot opt source destination
fail2ban-nginx-dos tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 80,443
fail2ban-nginx-404 tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 80,443
fail2ban-fusionpbx tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 80,443
fail2ban-freeswitch-404 all -- 0.0.0.0/0 0.0.0.0/0
fail2ban-freeswitch-dos-tcp tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 5060,5061,5080,5081
fail2ban-freeswitch-dos-udp udp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 5060,5061,5080,5081
fail2ban-freeswitch-tcp tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 5060,5061,5080,5081
fail2ban-freeswitch-udp udp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 5060,5061,5080,5081
fail2ban-freeswitch-udp udp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 5060,5061,5080,5081


2020-03-21 13:51:42.694025 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:42.694025 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:42.694025 [WARNING] sofia_reg.c:2906 Can't find user [5652@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="5652" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:42.694025 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [5652@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:43.434062 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [590@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:43.594027 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [3161@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:43.634040 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:43.634040 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:43.634040 [WARNING] sofia_reg.c:2906 Can't find user [590@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="590" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:43.634040 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [590@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:43.794011 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:43.794011 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:43.794011 [WARNING] sofia_reg.c:2906 Can't find user [3161@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="3161" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:43.794011 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [3161@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:44.974013 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [7035@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:45.194034 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:45.194034 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:45.194034 [WARNING] sofia_reg.c:2906 Can't find user [7035@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="7035" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:45.194034 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [7035@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:47.174035 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [7517@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:47.574053 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [726@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:47.794017 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:47.794017 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:47.794017 [WARNING] sofia_reg.c:2906 Can't find user [726@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="726" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:47.794017 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [726@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:49.014059 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [8039@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:49.234047 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:49.254005 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:49.254005 [WARNING] sofia_reg.c:2906 Can't find user [8039@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="8039" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:49.254005 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [8039@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:49.454023 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [5865@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:49.654022 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:49.654022 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:49.654022 [WARNING] sofia_reg.c:2906 Can't find user [5865@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="5865" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:49.654022 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [5865@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:50.874056 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [661@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:50.934051 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [2714@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:51.094068 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:51.094068 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:51.114002 [WARNING] sofia_reg.c:2906 Can't find user [661@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="661" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:51.114002 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [661@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:51.134049 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:51.134049 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:51.134049 [WARNING] sofia_reg.c:2906 Can't find user [2714@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="2714" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:51.134049 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [2714@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:51.934029 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [330@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:52.154032 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:52.154032 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:52.154032 [WARNING] sofia_reg.c:2906 Can't find user [330@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="330" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:52.154032 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [330@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:52.494027 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [4255@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:53.694037 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [983@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:56.314043 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [3794@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:56.514016 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:56.514016 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:56.514016 [WARNING] sofia_reg.c:2906 Can't find user [3794@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="3794" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:56.514016 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [3794@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:57.694056 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [3448@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:57.834095 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [2434@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:57.914004 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:57.914004 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:57.914004 [WARNING] sofia_reg.c:2906 Can't find user [3448@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="3448" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:57.914004 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [3448@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:58.794031 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [1121@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:59.014004 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:59.014004 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:59.014004 [WARNING] sofia_reg.c:2906 Can't find user [1121@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="1121" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:59.014004 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [1121@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:59.354031 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [3851@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:59.534074 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [1906@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:59.594004 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:59.594004 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:59.594004 [WARNING] sofia_reg.c:2906 Can't find user [3851@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="3851" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:59.594004 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [3851@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:51:59.754049 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:51:59.754049 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:51:59.754049 [WARNING] sofia_reg.c:2906 Can't find user [1906@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="1906" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:51:59.754049 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [1906@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:52:00.594180 [WARNING] sofia_reg.c:1792 SIP auth challenge (REGISTER) on sofia profile 'internal' for [4821@10.21.10.4] from ip 10.21.10.6
2020-03-21 13:52:00.814005 [DEBUG] freeswitch_lua.cpp:365 DBH handle 0x7f567c05d700 Connected.
2020-03-21 13:52:00.814005 [DEBUG] freeswitch_lua.cpp:382 DBH handle 0x7f567c05d700 released.
2020-03-21 13:52:00.814005 [WARNING] sofia_reg.c:2906 Can't find user [4821@10.21.10.4] from 10.21.10.6
You must define a domain called '10.21.10.4' in your directory and add a user with the id="4821" attribute
and you must configure your device to use the proper domain in it's authentication credentials.
2020-03-21 13:52:00.814005 [WARNING] sofia_reg.c:1737 SIP auth failure (REGISTER) on sofia profile 'internal' for [4821@10.21.10.4] from ip 10.21.10.6
 

DigitalDaz

Administrator
Staff member
Sep 29, 2016
3,070
577
113
I guess that's a conversation you need to be having with the supplier of the SBC, after all isn't that meant to be one of their functions?
 

DigitalDaz

Administrator
Staff member
Sep 29, 2016
3,070
577
113
You need this "SBC" to somehow pass you the original IP so you can deal with it."
 
Status
Not open for further replies.