Fine-tuning the firewall

When publishing a PBX on a public IP address, the task arises to protect the speaker from scanners, pests who are trying to pick up passwords to SIP PBX accounts. If a simple numeric password is set, it will be picked up very quickly, which will cause losses.

For basic protection against scanners, fail2ban must be enabled. Additionally, you can fine-tune the iptables rules.

  1. Go to the "System file customization" section

"System file customization" section
  1. Go to edit the /etc/firewall_additional file

File "/etc/firewall_additional"
  1. Set the "Add to end of file" mode, insert the following code:

The code for the file "/etc/firewall_additional"

A more complete example of a set of rules:

This will protect you from most scanners that I mention User-Agent when requesting.

Last updated

Was this helpful?