Brute force attack

ambi
Posts: 1
Member Since:
2011-03-31

Hi,

I am new to this forum, trying to find a solution for my issue. Our trixbox support contract is expired and I am trying to renew this.

Meantime, thought about posting the issue here.

I have a trixbox Pro Call Center Edition v4.1.2-p22 working fine, behind a firewall. Only remote offices are whitelisted for SIP. Unfortunately from past few days we are getting mails to our voicemail inbox from an internal extension 101 or asterisk. Before the support contract expired, I contacted the support team and they said, somebody is trying to bruteforce our system. As per their instructions, I whiltelisted our remote offices for SIP. I thought this fixed the issue, as we didn't received any more mails from the internal extension. After few days, it again started, and I am not sure how to stop this. Couple of forums, states an option to disable "anonymous SIP", but I couldn't find this in my trixbox control panel.

In few other forums I read about fail2ban but not really an expert in this. Would like to hear from you guys.

Please help me.