Fail2Ban is not blocking.

Asterisk 13.13.1
Fail2Ban v0.8.14

The full log showing:

[2017-02-08 08:41:03] WARNING[7204] chan_sip.c: Timeout on 008cb5e01383efde4e92ab9803f3cc0f on non-critical invite transaction.
[2017-02-08 08:41:16] WARNING[7204] chan_sip.c: Timeout on eaf846251b77037e78d0ae5d93dabacf on non-critical invite transaction.
[2017-02-08 08:45:27] WARNING[7204] chan_sip.c: Timeout on 8af01a7ccc185dbfafa8d839c7c91b49 on non-critical invite transaction.
[2017-02-08 08:49:38] WARNING[7204] chan_sip.c: Timeout on 29e5e69cc5535dc6625fb74ce4c9ec95 on non-critical invite transaction.
[2017-02-08 08:50:30] WARNING[7204] chan_sip.c: Timeout on 6633a54085b7a87613c3c021c835faec on non-critical invite transaction.
[2017-02-08 08:53:32] WARNING[7204] chan_sip.c: Timeout on 5ca8aeb1a05d2682c09cb41bee0921ee on non-critical invite transaction.
[2017-02-08 08:53:46] WARNING[7204] chan_sip.c: Timeout on 5d1d71ea466f3c180a66c1bdba9cd212 on non-critical invite transaction.
[2017-02-08 08:57:19] WARNING[7204] chan_sip.c: Timeout on d786d589bee69f293b321d1f568fd2e4 on non-critical invite transaction.
[2017-02-08 08:57:30] WARNING[7204] chan_sip.c: Timeout on c99af1a50c268b0312f9220bd32de0c1 on non-critical invite transaction.
[2017-02-08 08:58:00] WARNING[7204] chan_sip.c: Timeout on 8a61578698827f68c3c0d279606e2b71 on non-critical invite transaction.
[2017-02-08 09:05:47] WARNING[7204] chan_sip.c: Timeout on 0458b801505320c1cae998b7bc10bc12 on non-critical invite transaction.
[2017-02-08 09:06:31] WARNING[7204] chan_sip.c: Timeout on 04fabb502db9432fe140b9f64ce89e57 on non-critical invite transaction.
[2017-02-08 09:12:29] WARNING[7204] chan_sip.c: Timeout on b57cf59c2b44c26f75b6a0c927ac69fd on non-critical invite transaction.
[2017-02-08 09:18:43] WARNING[7204] chan_sip.c: Timeout on 482a266581150b9daa6c6a9a7422a3d5 on non-critical invite transaction.
[2017-02-08 09:19:10] WARNING[7204] chan_sip.c: Timeout on d08c8cd22d1e458463392f1075db4e69 on non-critical invite transaction.

The fail2ban log

 [2017-02-08 09:18:38] SECURITY[7210] res_security_log.c: SecurityEvent="ChallengeSent",EventTV="2017-02-08T09:18:38.968-0600",Severity="Informational",Service="SIP",EventVersion="1",AccountID="sip:[email protected]",SessionID="0x7fc800046b00",LocalAddress="IPV4/UDP/123.456.789.123/5060",RemoteAddress="IPV4/UDP/",Challenge="55797fb0"
 [2017-02-08 09:18:36] SECURITY[7210] res_security_log.c: SecurityEvent="ChallengeSent",EventTV="2017-02-08T09:18:36.866-0600",Severity="Informational",Service="SIP",EventVersion="1",AccountID="sip:[email protected]",SessionID="0x7fc8001246f0",LocalAddress="IPV4/UDP/123.456.789.123/5060",RemoteAddress="IPV4/UDP/",Challenge="3864c2fe"

After I added those 2 IPs (, manually to the recidive jail it stops. But during a night I can see 20-30 attempts. And those 2 are from today. Yesterday I had 2-3 different IPs


loglevel = 3

logtarget = /var/log/fail2ban.log

socket = /var/run/fail2ban/fail2ban.sock

pidfile = /var/run/fail2ban/


logtarget = /var/log/fail2ban.log


ignoreip =

# "bantime" is the number of seconds that a host is banned.
bantime  = 600

# A host is banned if it has generated "maxretry" during the last "findtime"
# seconds.
findtime  = 600

# "maxretry" is the number of failures before a host get banned.
maxretry = 3

backend = auto

usedns = warn

ignoreip = 123.456.789.123/24
bantime = 3600
findtime = 172800
maxretry = 3
backend = auto

enabled = true
filter = asterisk-security
action = iptables-allports[name=SIP, protocol=all]
     sendmail[name=SIP, dest=, [email protected]]
logpath = /var/log/asterisk/fail2ban

enabled = true
filter = freepbx
action = iptables-allports[name=SIP, protocol=all]
     sendmail[name=SIP, dest=, [email protected]]
logpath = /var/log/asterisk/freepbx_security.log

enabled = true
filter = sshd
action = iptables-multiport[name=SSH, protocol=tcp, port=ssh]
     sendmail[name=SSH, dest=, [email protected]]
logpath = /var/log/secure

enabled = true
filter = apache-auth
action = iptables-multiport[name=apache-auth, protocol=tcp, port=http]
     sendmail[name=apache-auth, dest=, [email protected]]
logpath = /var/log/httpd/error_log

enabled = true
filter = vsftpd
action = iptables-multiport[name=FTP, protocol=tcp, port=ftp]
     sendmail[name=FTP, dest=, [email protected]]
logpath = /var/log/vsftpd.log

enabled = true
filter = apache-badbots
action = iptables-multiport[name=BadBots, protocol=tcp, port="http,https"]
     sendmail[name=BadBots, dest=, [email protected]]
logpath = /var/log/httpd/*access_log

# recidivist.
#  Noun: A convicted criminal who reoffends, especially repeatedly.
enabled  = true
filter   = recidive
logpath  = /var/log/fail2ban.log*
action   = iptables-allports[name=recidive, protocol=all]
     sendmail[name=recidive, dest=, [email protected]]
bantime  = 604800  ; 1 week
findtime = 86400   ; 1 day
maxretry = 20


_daemon = asterisk

__pid_re = (?:\[\d+\])

iso8601 = \d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}\.\d+[+-]\d{4}

failregex = ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s Registration from '[^']*' failed for '<HOST>(:\d+)?' - (Wrong password|Username/auth name mismatch|No matching peer found|Not a local domain|Device does not match ACL|Peer is not supposed to register|ACL error \(permit/deny\)|Not a local domain)$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s Call from '[^']*' \(<HOST>:\d+\) to extension '[^']*' rejected because extension not found in context
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s Host <HOST> failed to authenticate as '[^']*'$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s No registration for peer '[^']*' \(from <HOST>\)$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s Host <HOST> failed MD5 authentication for '[^']*' \([^)]+\)$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s Failed to authenticate (user|device) [^@]+@<HOST>\S*$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s hacking attempt detected '<HOST>'$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s <HOST> tried to authenticate with nonexistent user.+$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s <HOST> failed to authenticate as.+$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s Request from '[^']*' failed for '<HOST>:\d+' .+ No matching endpoint found$
            ^(%(__prefix_line)s|\[\]\s*)%(log_prefix)s SecurityEvent="(FailedACL|InvalidAccountID|ChallengeResponseFailed|InvalidPassword)",EventTV="([\d-]+|%(iso8601)s)",Severity="[\w]+",Service="[\w]+",EventVersion="\d+",AccountID="(\d*|<unknown>)",SessionID=".+",LocalAddress="IPV[46]/(UDP|TCP|WS|WSS)/[\da-fA-F:.]+/\d+",RemoteAddress="IPV[46]/(UDP|TCP|WS|WSS)/<HOST>/\d+"(,Challenge="[\w/]+")?(,ReceivedChallenge="\w+")?(,Response="\w+",ExpectedResponse="\w*")?(,ReceivedHash="[\da-f]+")?(,ACLName="\w+")?$
[root@localhost ~]# iptables -L

Chain INPUT (policy ACCEPT)
target     prot opt source               destination
fail2ban-FTP  tcp  --  anywhere             anywhere            multiport dports                                                                           ftp
fail2ban-apache-auth  tcp  --  anywhere             anywhere            multipor                                                                        t dports http
fail2ban-SIP  all  --  anywhere             anywhere
fail2ban-SIP  all  --  anywhere             anywhere
fail2ban-BadBots  tcp  --  anywhere             anywhere            multiport dp                                                                        orts http,https
fail2ban-SSH  tcp  --  anywhere             anywhere            multiport dports                                                                         ssh
fail2ban-recidive  all  --  anywhere             anywhere

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

Chain fail2ban-BadBots (1 references)
target     prot opt source               destination
RETURN     all  --  anywhere             anywhere

Chain fail2ban-FTP (1 references)
target     prot opt source               destination
RETURN     all  --  anywhere             anywhere

Chain fail2ban-SIP (2 references)
target     prot opt source               destination
REJECT     all  --  anywhere            reject-with icmp                                                                        -port-unreachable
RETURN     all  --  anywhere             anywhere
RETURN     all  --  anywhere             anywhere

Chain fail2ban-SSH (1 references)
target     prot opt source               destination
REJECT     all  --  anywhere            reject-wit                                                                        h icmp-port-unreachable
REJECT     all  --        anywhere            reject-with icmp-po                                                                        rt-unreachable
RETURN     all  --  anywhere             anywhere

Chain fail2ban-apache-auth (1 references)
target     prot opt source               destination
RETURN     all  --  anywhere             anywhere

Chain fail2ban-recidive (1 references)
target     prot opt source               destination
REJECT     all  --   anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --        anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            reject-with icmp                                                                        -port-unreachable
REJECT     all  --       anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            reje                                                                        ct-with icmp-port-unreachable
REJECT     all  --      anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            reje                                                                        ct-with icmp-port-unreachable
REJECT     all  --  anywhere            rej                                                                        ect-with icmp-port-unreachable
REJECT     all  --  anywhere                                                                                    reject-with icmp-port-unreachable
REJECT     all  --   anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            r                                                                        eject-with icmp-port-unreachable
REJECT     all  --  anywhere            reject-with                                                                         icmp-port-unreachable
REJECT     all  --  anywhere            rej                                                                        ect-with icmp-port-unreachable
REJECT     all  --  anywhere            r                                                                        eject-with icmp-port-unreachable
REJECT     all  --      anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            rej                                                                        ect-with icmp-port-unreachable
REJECT     all  --      anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            reject-with ic                                                                        mp-port-unreachable
REJECT     all  --  anywhere            reject-w                                                                        ith icmp-port-unreachable
REJECT     all  --  anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --       anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            re                                                                        ject-with icmp-port-unreachable
REJECT     all  --  anywhere            reje                                                                        ct-with icmp-port-unreachable
REJECT     all  --  anywhere            reject-with i                                                                        cmp-port-unreachable
REJECT     all  --  anywhere            rejec                                                                        t-with icmp-port-unreachable
REJECT     all  --  anywhere            rej                                                                        ect-with icmp-port-unreachable
REJECT     all  --  anywhere            rejec                                                                        t-with icmp-port-unreachable
REJECT     all  --  anywhere            reject-wi                                                                        th icmp-port-unreachable
REJECT     all  --         anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --      anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            reje                                                                        ct-with icmp-port-unreachable
REJECT     all  --        anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --        anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere                                                                                    reject-with icmp-port-unreachable
REJECT     all  --  anywhere            reject-with                                                                         icmp-port-unreachable
REJECT     all  --        anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            reject-with icmp-                                                                        port-unreachable
REJECT     all  --      anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            reject-with                                                                         icmp-port-unreachable
REJECT     all  --  anywhere            reject-with                                                                         icmp-port-unreachable
REJECT     all  --  anywhere            reject                                                                        -with icmp-port-unreachable
REJECT     all  --           anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --       anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --      anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --      anywhere            reject-with icmp-po                                                                        rt-unreachable
REJECT     all  --  anywhere            rejec                                                                        t-with icmp-port-unreachable
RETURN     all  --  anywhere             anywhere

Any ideas ? Fail2Ban was reinstalled but still nothing