UCM6200 Series User Manual 
 
Figure 41: Configure Dynamic Defense 
Fail2ban 
 
Fail2Ban feature on the UCM6200 provides intrusion detection and prevention for authentication errors in SIP 
REGISTER, INVITE and SUBSCRIBE. Once the entry is detected within "Max Retry Duration", the UCM6200 
will take action to forbid the host for certain period as defined in "Banned Duration". This feature helps prevent 
SIP brute force attacks to the PBX system. 
 
Table 18: Fail2Ban Settings 
Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable 
Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP 
authentication on the UCM6200. 
Configure the duration (in seconds) for the detected host to be banned. The default 
setting is 300. If set to -1, the host will be always banned. 
Within  this  duration  (in  seconds),  if  a  host  exceeds  the  max  times  of  retry  as 
defined in "MaxRetry", the host will be banned. The default setting is 5. 
Configure the number of authentication failures during "Max Retry Duration" before 
the host is banned. The default setting is 10. 
Configure IP address, CIDR mask or DNS host in the whitelist. Fail2Ban will not 
ban the host with matching address in this list. Up to 5 addresses can be added 
into the list. 
Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make 
sure both "Enable Fail2Ban" and "Asterisk Service" are turned on in order to use 
Fail2Ban for SIP authentication on the UCM6200. 
Configure the listening port number for the service. Currently only 5060 (for UDP)