<div dir="ltr">Boa Tarde<div><br></div><div>Cara, eu uso esse script para instalar nos meus servidores. Em todos os meus funcionam</div><div><br></div><div><div>apt-get -y install fail2ban</div><div>echo &quot;[asterisk-iptables]&quot; &gt;&gt; /etc/fail2ban/jail.conf</div>
<div>echo &quot;enabled = true&quot; &gt;&gt; /etc/fail2ban/jail.conf</div><div>echo &quot;filter = asterisk&quot; &gt;&gt; /etc/fail2ban/jail.conf</div><div>echo &quot;action = iptables-allports[name=ASTERISK, protocol=all]&quot; &gt;&gt; /etc/fail2ban/jail.conf</div>
<div>echo &quot;sendmail-whois[name=ASTERISK, dest=root, sender=<a href="mailto:fail2ban@example.org">fail2ban@example.org</a>]&quot; &gt;&gt; /etc/fail2ban/jail.conf</div><div>echo &quot;logpath = /var/log/asterisk/messages&quot; &gt;&gt; /etc/fail2ban/jail.conf</div>
<div>sed -i &#39;s/bantime  = 600/bantime  = 7600/g&#39; /etc/fail2ban/jail.conf</div><div>sed -i &#39;s/maxretry = 3/maxretry = 6/g&#39; /etc/fail2ban/jail.conf</div><div>touch /etc/fail2ban/filter.d/asterisk.conf</div><div>
echo &quot;&quot; &gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>echo &quot;[INCLUDES]&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>echo &quot;&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div>
<div>echo &quot;[Definition]&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>echo &quot;failregex = ^.* .*NOTICE.* .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Wrong password&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div>
<div>echo &quot;           ^.* .*NOTICE.* .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - No matching peer found&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>echo &quot;           ^.* .*NOTICE.* .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Username/auth name mismatch&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div>
<div>echo &quot;           ^.* .*NOTICE.* .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Device does not match ACL&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>echo &quot;           ^.* .*NOTICE.* &lt;HOST&gt; failed to authenticate as &#39;.*&#39;\$&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div>
<div>echo &quot;           ^.* .*NOTICE.* .*: No registration for peer &#39;.*&#39; \(from &lt;HOST&gt;\)&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>echo &quot;           ^.* .*NOTICE.* .*: Host &lt;HOST&gt; failed MD5 authentication for &#39;.*&#39; (.*)&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div>
<div>echo &quot;           ^.* .*NOTICE.* .*: Failed to authenticate user .*@&lt;HOST&gt;.*&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>echo &quot;           ^.* .*NOTICE.* .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Device not configured to use this transport type&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div>
<div>echo &quot;           ^.* .*NOTICE.* .*: .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Device not configured to use this transport type&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div>
<div>echo &quot;ignoreregex =&quot; &gt;&gt; /etc/fail2ban/filter.d/asterisk.conf</div><div>sed -i &#39;s/dateformat=.*/dateformat=%F %T/g&#39; /etc/asterisk/logger.conf</div><div>sed -i &#39;/^messages/d&#39; /etc/asterisk/logger.conf</div>
<div>echo &quot;messages =&gt; verbose,warning,error,notice&quot; &gt;&gt; /etc/asterisk/logger.conf</div><div>asterisk -rx &quot;logger reload&quot;</div><div><br></div><div class="gmail_extra"><br><br><div class="gmail_quote">
On Mon, Feb 4, 2013 at 11:36 AM, Silvio Garbes <span dir="ltr">&lt;<a href="mailto:silviogarbes@gmail.com" target="_blank">silviogarbes@gmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
Em resposta a mensagem de &quot;João Marcelo Queiroz&quot; na pergunta de &quot;Fail2Ban não bloqueia ataque&quot; em &quot;Quarta Janeiro 5 10:40:26 BRST 2011&quot;.<div><br></div><div>Estive com o mesmo problema e descobri que da versão 1.8 do asterisk para a versão 1.4 deve-se alterar o arquivo &quot;/etc/fail2ban/filter.d/asterisk.conf&quot;. No log do asterisk da versão 1.8 ou superior a porta de destino vem junto com o log.</div>


<div><br></div><div>De:</div><div><div>failregex = NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Wrong password$</div><div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - No matching peer found$</div>


<div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Username/auth name mismatch$</div><div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Device does not match ACL$</div>


<div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - Peer is not supposed to register$</div><div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;&#39; - ACL error (permit/deny)$</div>


<div>            NOTICE%(__pid_re)s &lt;HOST&gt; failed to authenticate as &#39;.*&#39;$</div><div>            NOTICE%(__pid_re)s .*: No registration for peer &#39;.*&#39; \(from &lt;HOST&gt;\)$</div><div>            NOTICE%(__pid_re)s .*: Host &lt;HOST&gt; failed MD5 authentication for &#39;.*&#39; (.*)$</div>


<div>            NOTICE%(__pid_re)s .*: Failed to authenticate user .*@&lt;HOST&gt;.*$</div></div><div><br></div><div><br></div><div>Para:</div><div><div>failregex = NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;:.*&#39; - Wrong password$</div>


<div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;:.*&#39; - No matching peer found$</div><div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;:.*&#39; - Username/auth name mismatch$</div>


<div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;:.*&#39; - Device does not match ACL$</div><div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;:.*&#39; - Peer is not supposed to register$</div>


<div>            NOTICE%(__pid_re)s .*: Registration from &#39;.*&#39; failed for &#39;&lt;HOST&gt;:.*&#39; - ACL error (permit/deny)$</div><div>            NOTICE%(__pid_re)s &lt;HOST&gt; failed to authenticate as &#39;.*&#39;$</div>


<div>            NOTICE%(__pid_re)s .*: No registration for peer &#39;.*&#39; \(from &lt;HOST&gt;\)$</div><div>            NOTICE%(__pid_re)s .*: Host &lt;HOST&gt; failed MD5 authentication for &#39;.*&#39; (.*)$</div><div>


            NOTICE%(__pid_re)s .*: Failed to authenticate user .*@&lt;HOST&gt;.*$</div></div><div><br></div><div><br clear="all"><div>Cordialmente,<br><br>Sílvio Garbes Lara<br><br></div>
</div>
<br>_______________________________________________<br>
EBS MODULAR: 3 slots para combinação entre E1, GSM, FXS ou FXO;<br>
Linha de PORTEIROS IP, abrem até 2 dispositivos com acesso IP remoto;<br>
Conheça esses e outros LANÇAMENTOS KHOMP em <a href="http://www.Khomp.com" target="_blank">www.Khomp.com</a> <br>
_______________________________________________<br>
DIGIVOICE  Fabricante de Placas de Voz e Channel Bank<br>
20 anos de experiência com E1(R2/ISDN), FXS, FXO e GSM<br>
Centro Treinamento - Curso de PABX IP -  Asterisk  - Site  <a href="http://www.digivoice.com.br" target="_blank">www.digivoice.com.br</a><br>
_______________________________________________<br>
ALIGERA – Fabricante nacional de Gateways SIP-E1 para R2, ISDN e SS7.<br>
Placas de 1E1, 2E1, 4E1 e 8E1 para PCI ou PCI Express.<br>
Channel Bank – Appliance Asterisk - Acesse <a href="http://www.aligera.com.br" target="_blank">www.aligera.com.br</a>.<br>
_______________________________________________<br>
Para remover seu email desta lista, basta enviar um email em branco para <a href="mailto:asteriskbrasil-unsubscribe@listas.asteriskbrasil.org">asteriskbrasil-unsubscribe@listas.asteriskbrasil.org</a><br></blockquote></div>
<br><br clear="all"><div><br></div>-- <br>___________________________________________<br>André Luis Peres Ribeiro     16 92340876
</div></div></div>