Created byPaul Timms13:21 29 July 2020
From my own experience:
- You should clearly have a firewall running on the server hosting Asterisk.
- fail2ban should be installed and active
- Port 5038 (Asterisk Manager Interface) should only be open to the server running Standard ERP, if it's not
Thanks. Fail2ban does not always help (maybe it is already fixed, don't know) https://forums.asterisk.org/viewtopic.php?p=159984:
It is also worth mentioning, if people used type=peer instead of type=friend, none of these attacks would have a chance of succeeding as type=peer forces registration which fail2ban already knows how to protect.