P a g e | 83
UCM6510 IP PBX User Manual
Version 1.0.20.31
Table 15: Fail2Ban Settings
Enable Fail2Ban. The default setting is disabled. Please make sure both “Enable
Fail2Ban” and “Asterisk Service” are turned on to use Fail2Ban for SIP
authentication on the UCM6510.
Configure the duration (in seconds) for the detected host to be banned. The default
setting is 600. If set to 0, the host will be always banned.
If a host exceeds the maximum allowed number attempts configured for Max Retry
within the configured Max Retry Duration window, the host will be banned. The
default setting is 600 seconds.
Configures the maximum number of allowed authentication failures within the
configured Max Retry Duration window. The default setting is 5.
Configures the IP addresses, CIDR masks, and DNS hosts in the Fail2Ban whitelist.
Whitelisted entries will not be banned by Fail2Ban even after exceeding the allowed
number of authentication failures. Up to 20 addresses can be added.
Enable Asterisk service for Fail2Ban. The default setting is disabled. Please make
sure both “Enable Fail2Ban” and “Asterisk Service” are turned on to use Fail2Ban
for SIP authentication on the UCM6510.
Configure the listening port number for the service. By default, port 5060 will be
used for UDP and TCP, and port 5061 will be used for TLS.
Configures the maximum number of authentication failures before the host is
banned. The default setting is 10. Please note that this will override the Global
SettingsMaxRetry setting.
Enables defense against excessive login attacks to the UCM’s web GUI.
The default setting is disabled.
This is the Web GUI listening port number which is configured under System
SettingsHTTP ServerPort. The default is 8089.
Configures the maximum allowed number of failed login attempts from an IP
address before it is added to the Fail2Ban blacklist.
Users will be able to view the IPs that have been blocked by UCM.
TLS Security
SSH access can be toggled from the UCM's webUI and physical LCD screen. The webUI option can be
found under System SettingsSecurity Settings-SSH Access. SSH access is disabled by default and
should only be turned on for troubleshooting and debugging.