<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Asterisk - Asterisk on DevOps and application security enthusiast's notes</title><link>https://erudinsky.com/categories/asterisk---asterisk/</link><description>Recent content in Asterisk - Asterisk on DevOps and application security enthusiast's notes</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 22 Dec 2015 07:00:00 +0100</lastBuildDate><atom:link href="https://erudinsky.com/categories/asterisk---asterisk/index.xml" rel="self" type="application/rss+xml"/><item><title>Fail2ban with Asterisk 13</title><link>https://erudinsky.com/2015/12/22/fail2ban-with-asterisk-13/</link><pubDate>Tue, 22 Dec 2015 07:00:00 +0100</pubDate><guid>https://erudinsky.com/2015/12/22/fail2ban-with-asterisk-13/</guid><description>&lt;p&gt;Even having fresh AWS EC2 instance with either fixed or not IP, I start seeing constant attempts to get access to my SIP server. Brute force attacks are very famous and now I&amp;rsquo;m going to change this in my server by setting Fail2Ban in place.&lt;/p&gt;
&lt;h2 id="prepare-asterisk-loggerconf"&gt;Prepare Asterisk (logger.conf) &lt;a class="heading-anchor" href="#prepare-asterisk-loggerconf" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&lt;p&gt;Uncomment the following in your &lt;code&gt;/etc/asterisk/logger.conf&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#282a36;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;display:grid;"&gt;&lt;code class="language-markdown" data-lang="markdown"&gt;&lt;span style="display:flex;"&gt;&lt;span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f"&gt;1&lt;/span&gt;&lt;span&gt;[general]
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f"&gt;2&lt;/span&gt;&lt;span&gt;dateformat = %F %T
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f"&gt;3&lt;/span&gt;&lt;span&gt;...
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f"&gt;4&lt;/span&gt;&lt;span&gt;[logfiles]
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f"&gt;5&lt;/span&gt;&lt;span&gt;security = security
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="installing-and-configuring-fail2ban-using-apt-get-manager"&gt;Installing and configuring fail2ban using apt-get manager &lt;a class="heading-anchor" href="#installing-and-configuring-fail2ban-using-apt-get-manager" aria-label="Link to this section"&gt;#&lt;/a&gt;&lt;/h2&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#282a36;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;display:grid;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f"&gt;1&lt;/span&gt;&lt;span&gt;sudo apt-get update
&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f"&gt;2&lt;/span&gt;&lt;span&gt;apt-get install fail2ban
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once finished, let&amp;rsquo;s add the following to the end of &lt;code&gt;/etc/fail2ban/jail.conf&lt;/code&gt;. Feel free to change numbers (they are self-explained).&lt;/p&gt;</description></item></channel></rss>