Em resposta a mensagem de "João Marcelo Queiroz" na pergunta de "Fail2Ban não bloqueia ataque" em "Quarta Janeiro 5 10:40:26 BRST 2011".<div><br></div><div>Estive com o mesmo problema e descobri que da versão 1.8 do asterisk para a versão 1.4 deve-se alterar o arquivo "/etc/fail2ban/filter.d/asterisk.conf". No log do asterisk da versão 1.8 ou superior a porta de destino vem junto com o log.</div>
<div><br></div><div>De:</div><div><div>failregex = NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>' - Wrong password$</div><div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>' - No matching peer found$</div>
<div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>' - Username/auth name mismatch$</div><div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>' - Device does not match ACL$</div>
<div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>' - Peer is not supposed to register$</div><div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>' - ACL error (permit/deny)$</div>
<div> NOTICE%(__pid_re)s <HOST> failed to authenticate as '.*'$</div><div> NOTICE%(__pid_re)s .*: No registration for peer '.*' \(from <HOST>\)$</div><div> NOTICE%(__pid_re)s .*: Host <HOST> failed MD5 authentication for '.*' (.*)$</div>
<div> NOTICE%(__pid_re)s .*: Failed to authenticate user .*@<HOST>.*$</div></div><div><br></div><div><br></div><div>Para:</div><div><div>failregex = NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>:.*' - Wrong password$</div>
<div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>:.*' - No matching peer found$</div><div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>:.*' - Username/auth name mismatch$</div>
<div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>:.*' - Device does not match ACL$</div><div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>:.*' - Peer is not supposed to register$</div>
<div> NOTICE%(__pid_re)s .*: Registration from '.*' failed for '<HOST>:.*' - ACL error (permit/deny)$</div><div> NOTICE%(__pid_re)s <HOST> failed to authenticate as '.*'$</div>
<div> NOTICE%(__pid_re)s .*: No registration for peer '.*' \(from <HOST>\)$</div><div> NOTICE%(__pid_re)s .*: Host <HOST> failed MD5 authentication for '.*' (.*)$</div><div>
NOTICE%(__pid_re)s .*: Failed to authenticate user .*@<HOST>.*$</div></div><div><br></div><div><br clear="all"><div>Cordialmente,<br><br>Sílvio Garbes Lara<br><br></div>
</div>