FreePBX | Register | Issues | Wiki | Portal | Support

FreePBX Console Down (again)


(Mark Moore) #1

For the second time in a month, the main FreePBX page is not responding. I can ping the IP, and I can ssh in. But, the main page with admin, user, and (i forget what) doesn’t come up.

Here is the tail of /var/log/asterisk/full:

[2019-07-11 18:27:27] NOTICE[18118] res_pjsip/pjsip_distributor.c: Request ‘REGISTER’ from ‘“22222” sip:22222@162.255.22.40’ failed for ‘64.31.33.70:5129’ (callid: 3637370258) - No matching endpoint found after 76 tries in 2.615 ms
[2019-07-11 18:27:27] NOTICE[18118] res_pjsip/pjsip_distributor.c: Request ‘REGISTER’ from ‘“22222” sip:22222@162.255.22.40’ failed for ‘64.31.33.70:5129’ (callid: 3637370258) - Failed to authenticate
[2019-07-11 18:27:27] NOTICE[18367] res_pjsip/pjsip_distributor.c: Request ‘REGISTER’ from ‘“22222” sip:22222@162.255.22.40’ failed for ‘64.31.33.70:5129’ (callid: 1980991538) - No matching endpoint found after 77 tries in 2.626 ms
[2019-07-11 18:27:27] NOTICE[18367] res_pjsip/pjsip_distributor.c: Request ‘REGISTER’ from ‘“22222” sip:22222@162.255.22.40’ failed for ‘64.31.33.70:5129’ (callid: 1980991538) - Failed to authenticate
[2019-07-11 18:30:00] NOTICE[13415][C-000121e0] chan_sip.c: Failed to authenticate device sip:1400@162.255.22.40;tag=1202615807
[2019-07-11 18:30:32] WARNING[13415] chan_sip.c: Retransmission timeout reached on transmission 391820599-2091038238-2110727117 for seqno 2 (Critical Response) – See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 32000ms with no response
[2019-07-11 18:36:41] NOTICE[13415][C-000121e1] chan_sip.c: Failed to authenticate device sip:1400@162.255.22.40;tag=2054821797
[2019-07-11 18:37:13] WARNING[13415] chan_sip.c: Retransmission timeout reached on transmission 1482961483-975384261-1698742275 for seqno 2 (Critical Response) – See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 31999ms with no response
[markm@pbx ~]$ tail /var/log/asterisk/full -f
[2019-07-11 18:27:27] NOTICE[18367] res_pjsip/pjsip_distributor.c: Request ‘REGISTER’ from ‘“22222” sip:22222@162.255.22.40’ failed for ‘64.31.33.70:5129’ (callid: 1980991538) - Failed to authenticate
[2019-07-11 18:30:00] NOTICE[13415][C-000121e0] chan_sip.c: Failed to authenticate device sip:1400@162.255.22.40;tag=1202615807
[2019-07-11 18:30:32] WARNING[13415] chan_sip.c: Retransmission timeout reached on transmission 391820599-2091038238-2110727117 for seqno 2 (Critical Response) – See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 32000ms with no response
[2019-07-11 18:36:41] NOTICE[13415][C-000121e1] chan_sip.c: Failed to authenticate device sip:1400@162.255.22.40;tag=2054821797
[2019-07-11 18:37:13] WARNING[13415] chan_sip.c: Retransmission timeout reached on transmission 1482961483-975384261-1698742275 for seqno 2 (Critical Response) – See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 31999ms with no response
[2019-07-11 18:42:46] NOTICE[13415][C-000121e2] chan_sip.c: Failed to authenticate device sip:1400@162.255.22.40;tag=654665403
[2019-07-11 18:43:18] WARNING[13415] chan_sip.c: Retransmission timeout reached on transmission 239477683-1581772608-899270055 for seqno 2 (Critical Response) – See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 31999ms with no response
[2019-07-11 18:49:19] NOTICE[13415][C-000121e3] chan_sip.c: Failed to authenticate device sip:1400@162.255.22.40;tag=13840597
[2019-07-11 18:49:51] WARNING[13415] chan_sip.c: Retransmission timeout reached on transmission 532475492-592657398-218317976 for seqno 2 (Critical Response) – See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 32000ms with no response
[2019-07-11 18:55:56] NOTICE[13415][C-000121e4] chan_sip.c: Failed to authenticate device sip:1400@162.255.22.40;tag=551441412
[2019-07-11 18:56:28] WARNING[13415] chan_sip.c: Retransmission timeout reached on transmission 184584252-359635382-1882398208 for seqno 2 (Critical Response) – See https://wiki.asterisk.org/wiki/display/AST/SIP+Retransmissions
Packet timed out after 32000ms with no response

Here is fwconsole ma list:

+----------------------+------------+---------+------------+
| Module               | Version    | Status  | License    |
+----------------------+------------+---------+------------+
| accountcodepreserve  | 13.0.2.2   | Enabled | GPLv2      |
| amd                  | 13.0.3     | Enabled | GPLv3+     |
| announcement         | 13.0.7.7   | Enabled | GPLv3+     |
| areminder            | 14.0.4.13  | Enabled | Commercial |
| arimanager           | 13.0.5.2   | Enabled | GPLv3+     |
| asterisk-cli         | 14.0.1     | Enabled | GPLv3+     |
| asteriskinfo         | 13.0.7.1   | Enabled | GPLv3+     |
| backup               | 14.0.10.3  | Enabled | GPLv3+     |
| blacklist            | 14.0.2     | Enabled | GPLv3+     |
| broadcast            | 14.0.1.12  | Enabled | Commercial |
| builtin              |            | Enabled |            |
| bulkhandler          | 13.0.14.8  | Enabled | GPLv3+     |
| calendar             | 14.0.2.16  | Enabled | GPLv3+     |
| callback             | 13.0.5.4   | Enabled | GPLv3+     |
| callerid             | 13.0.8.16  | Enabled | Commercial |
| callforward          | 14.0.1.3   | Enabled | AGPLv3+    |
| calllimit            | 13.0.5.7   | Enabled | Commercial |
| callrecording        | 14.0.14    | Enabled | AGPLv3+    |
| callwaiting          | 14.0.1.1   | Enabled | GPLv3+     |
| campon               | 13.0.4.1   | Enabled | GPLv3+     |
| cdr                  | 14.0.5.19  | Enabled | GPLv3+     |
| cel                  | 14.0.2.12  | Enabled | GPLv3+     |
| certman              | 14.0.3.2   | Enabled | AGPLv3+    |
| cidlookup            | 14.0.1.8   | Enabled | GPLv3+     |
| conferences          | 13.0.23.15 | Enabled | GPLv3+     |
| conferencespro       | 14.0.2.9   | Enabled | Commercial |
| configedit           | 13.0.7.1   | Enabled | AGPLv3+    |
| contactmanager       | 14.0.5.4   | Enabled | GPLv3+     |
| core                 | 14.0.25.4  | Enabled | GPLv3+     |
| cos                  | 13.0.12.5  | Enabled | Commercial |
| customappsreg        | 13.0.5.7   | Enabled | GPLv3+     |
| cxpanel              | 14.0.2     | Enabled | GPLv3      |
| dahdiconfig          | 14.0.1.4   | Enabled | GPLv3+     |
| dashboard            | 14.0.6.2   | Enabled | AGPLv3+    |
| daynight             | 14.0.1     | Enabled | GPLv3+     |
| dictate              | 13.0.5     | Enabled | GPLv3+     |
| digium_phones        | 13.0.7.4   | Enabled | GPLv2      |
| digiumaddoninstaller | 13.0.1.1   | Enabled | GPLv2      |
| directory            | 13.0.19.12 | Enabled | GPLv3+     |
| disa                 | 13.0.6.12  | Enabled | AGPLv3+    |
| donotdisturb         | 14.0.1.1   | Enabled | GPLv3+     |
| dundicheck           | 2.11.0.3   | Enabled | GPLv3+     |
| endpoint             | 14.0.9     | Enabled | Commercial |
| extensionroutes      | 13.0.10.7  | Enabled | Commercial |
| extensionsettings    | 13.0.4     | Enabled | GPLv3+     |
| fax                  | 14.0.2.7   | Enabled | GPLv3+     |
| faxpro               | 14.0.8     | Enabled | Commercial |
| featurecodeadmin     | 13.0.6.4   | Enabled | GPLv3+     |
| findmefollow         | 14.0.1.23  | Enabled | GPLv3+     |
| firewall             | 13.0.57.1  | Enabled | AGPLv3+    |
| framework            | 14.0.13.4  | Enabled | GPLv2+     |
| freepbx_ha           | 13.0.11    | Enabled | Commercial |
| fw_langpacks         | 14.0.1     | Enabled | GPLv3+     |
| hotelwakeup          | 14.0.1.6   | Enabled | GPLv2      |
| iaxsettings          | 14.0.1.4   | Enabled | AGPLv3     |
| infoservices         | 13.0.1.4   | Enabled | GPLv2+     |
| irc                  | 13.0.1     | Enabled | GPLv3+     |
| ivr                  | 14.0.4     | Enabled | GPLv3+     |
| languages            | 14.0.1.4   | Enabled | GPLv3+     |
| logfiles             | 13.0.10.5  | Enabled | GPLv3+     |
| manager              | 13.0.2.5   | Enabled | GPLv2+     |
| miscapps             | 13.0.3.1   | Enabled | GPLv3+     |
| miscdests            | 13.0.7     | Enabled | GPLv3+     |
| motif                | 13.0.3.2   | Enabled | GPLv3+     |
| music                | 13.0.22.7  | Enabled | GPLv3+     |
| outroutemsg          | 14.0.1     | Enabled | GPLv3+     |
| paging               | 14.0.12    | Enabled | GPLv3+     |
| pagingpro            | 14.0.2.15  | Enabled | Commercial |
| parking              | 13.0.19.11 | Enabled | GPLv3+     |
| parkpro              | 14.0.2.9   | Enabled | Commercial |
| pbdirectory          | 2.11.0.6   | Enabled | GPLv3+     |
| phonebook            | 13.0.6.4   | Enabled | GPLv3+     |
| phpinfo              | 13.0.2     | Enabled | GPLv2+     |
| pinsets              | 13.0.13    | Enabled | GPLv3+     |
| pinsetspro           | 13.0.9.14  | Enabled | Commercial |
| pm2                  | 13.0.7.1   | Enabled | AGPLv3+    |
| pms                  | 14.0.2.37  | Enabled | Commercial |
| presencestate        | 14.0.1.7   | Enabled | GPLv3+     |
| printextensions      | 13.0.3.2   | Enabled | GPLv3+     |
| queuemetrics         | 2.11.0.3   | Enabled | GPLv3+     |
| queueprio            | 13.0.6     | Enabled | GPLv3+     |
| queues               | 14.0.2.25  | Enabled | GPLv2+     |
| queuestats           | 14.0.1.4   | Enabled | Commercial |
| recording_report     | 14.0.2.4   | Enabled | Commercial |
| recordings           | 13.0.30.13 | Enabled | GPLv3+     |
| restapi              | 13.0.21.2  | Enabled | AGPLv3     |
| restapps             | 14.0.1     | Enabled | Commercial |
| ringgroups           | 14.0.1.8   | Enabled | GPLv3+     |
| sangomacrm           | 14.0.2.5   | Enabled | Commercial |
| setcid               | 13.0.6.3   | Enabled | GPLv3+     |
| sipsettings          | 14.0.27.12 | Enabled | AGPLv3+    |
| sipstation           | 14.0.3     | Enabled | Commercial |
| sms                  | 14.0.4.6   | Enabled | Commercial |
| soundlang            | 14.0.7     | Enabled | GPLv3+     |
| speeddial            | 2.11.0.4   | Enabled | GPLv3+     |
| superfecta           | 14.0.18    | Enabled | GPLv2+     |
| sysadmin             | 14.0.33    | Enabled | Commercial |
| timeconditions       | 14.0.2.17  | Enabled | GPLv3+     |
| tts                  | 13.0.13    | Enabled | GPLv3+     |
| ttsengines           | 13.0.7.5   | Enabled | AGPLv3     |
| ucp                  | 14.0.3.3   | Enabled | AGPLv3+    |
| userman              | 14.0.3.49  | Enabled | AGPLv3+    |
| versionupgrade       | 14.0.3     | Enabled | Commercial |
| vmblast              | 13.0.11    | Enabled | GPLv3+     |
| vmnotify             | 14.0.1.5   | Enabled | Commercial |
| voicemail            | 14.0.6.6   | Enabled | GPLv3+     |
| voicemail_report     | 13.0.13.3  | Enabled | Commercial |
| vqplus               | 14.0.1.36  | Enabled | Commercial |
| weakpasswords        | 13.0.2     | Enabled | GPLv3+     |
| webcallback          | 13.0.11.5  | Enabled | Commercial |
| webrtc               | 14.0.3.8   | Enabled | GPLv3+     |
| xmpp                 | 14.0.1.19  | Enabled | AGPLv3     |
| zulu                 | 14.0.56.16 | Enabled | Commercial |
+----------------------+------------+---------+------------+

I’m pretty sure when I reboot the server that it will fix the problem, but I’d like to diagnose the problem before. I would expect it to be much more stable than this.


(Dave Burgess) #2

This is either a hack attempt or you’ve got a SIP extension trying to connect on the PJ-SIP port. If you know who this is, you can update the extension to use PJ-SIP and that should be that.

If it’s a hack attempt, time to turn on your firewall (assuming you can) or turn on the Adaptive Firewall (assuming you need to) to block people that aren’t supposed to be logging in.

This is usually a NAT/Router setup problem. Check the URL for more information.

You might also try going into Asterisk Reports and looking at the SIP stuff to see how many open connections you are processing.

Note that, unless your console is also trying to log into a phone, this stuff has nothing to do with your locked out console.

Make sure your modules and Asterisk executable are all up-to-date and you aren’t running one of the versions that locked the system up.


(Jared Busch) #3

I am randomly unable to get my PBX to load in Firefox. But if I delete the cookies for the domain, it loads immediately.

I’ve never had it happen with any other PBX that I log into except my company’s.

Did you whitelist your network in the Intrusion Detection section of the SysAdmin Module?
That is the biggest annoyance I have. Intrusion Detection is a separate whitelist from the networks you set up in the Firewall.


#4

interesting, i have seen these buggers before . . .

whois 64.31.33.70

gives very questionable results . including

.
.
.
Found a referral to rwhois.limestonenetworks.com:4321.

%rwhois V-1.5:003fff:00 rwhois.limestonenetworks.com (by Network Solutions, Inc. V-1.5.9.5)
network:Class-Name:network
network:ID:LSN-BLK-64.31.0.0/18
network:Auth-Area:64.31.0.0/18
network:Network-Name:LSN-64.31.0.0/18
network:IP-Network:64.31.33.68/30
network:IP-Network-Block:64.31.33.68 - 64.31.33.71
network:Organization-Name:Dream Mohammed Zourob
network:Organization-City:Palestine
network:Organization-State:OT
network:Organization-Zip:na
network:Organization-Country:IN
network:Tech-Contact;I:abuse@limestonenetworks.com
network:Admin-Contact;I:abuse@limestonenetworks.com
network:Updated-By:admin@limestonenetworks.com
.
.
.

To see what else is going on

tcpdump net 64.31.0.0/18

limestone networks (64.31.0.0/18)

I would drop that network at your firewall.

as to exten 1400, do you have an account at cyberlink (sipstation) ? because you cant get to 162.255.16.0/21 which should not be blocked if so. possibly fail2ban is kicking in, add that network to ignoreip


(Mark Moore) #5

Thanks all for responding. I’m new to Asterisk/FreePBX/Sangoma/FreePBXHosting (but a fast learner).

@cynjut, this is definitely a hack attempt. I had an earlier post on a huge number of “PJSIP/anonymous-000xxxxx” calls.[1]

It’s not a NAT/Router problem. I’m running a cloud server under FreePBXHosting.com. Also, it’s been working spectacularly well for the last month (except for the 2 times it has barfed on its shirt).

I can’t go to Asterisk Reports because I can’t even get the HTTP server to respond.

All modules were up to date (no outstanding messages either at the Dashboard), and when I login to ssh, there are no modules that need to be updated.

I’ll try and crank down the firewall.

@sorvani, thanks for the thought. This failure is independent of the browser. I went ahead and deleted cookies, but that didn’t change anything.

We do not whitelist (yet).

@dicko, I think you’re spot on. This looks like a hack attempt. I’m going to reboot and then tighten up the firewall.

We do get our trunks from SIPSTATION. I don’t have any problem logging into my account there, but that is run by a completely separate server, so I’m not surprised at that.

In case it wasn’t clear in my OP, the problem I’m having is that https://162.255.22.40 isn’t responding at all. To reproduce my failure, just click on that link and watch the timeout.

Here is what curl -I https://162.255.22.40 returns:

Date: Fri, 12 Jul 2019 00:18:19 GMT
Server: Apache/2.4.6 (Sangoma) OpenSSL/1.0.2k-fips PHP/5.6.40
X-Powered-By: PHP/5.6.40
Location: /admin
Content-Type: text/html; charset=UTF-8

[1] Huge Number of Incoming Calls


#6

cat /var/log/fail2ban.log*

(or whatever file fail2ban is logging to in your OS)


(Mark Moore) #7
2019-07-11 04:02:09,077 fail2ban.server [13092]: INFO    Changed logging target to /var/log/fail2ban.log for Fail2ban v0.8.14
2019-07-11 04:02:10,787 fail2ban.filter [13092]: ERROR   Unable to open /var/log/fail2ban.log-20190627
2019-07-11 04:02:10,787 fail2ban.filter [13092]: ERROR   [Errno 2] No such file or directory: '/var/log/fail2ban.log-20190627'
Traceback (most recent call last):
  File "/usr/share/fail2ban/server/filter.py", line 556, in getFailures
    has_content = container.open()
  File "/usr/share/fail2ban/server/filter.py", line 637, in open
    self.__handler = open(self.__filename)
IOError: [Errno 2] No such file or directory: '/var/log/fail2ban.log-20190627'
2019-07-11 04:03:04,055 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 04:14:27,278 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 198.98.62.146
2019-07-11 04:15:57,390 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 122.195.200.148
2019-07-11 04:16:43,105 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 04:16:45,469 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.236.151
2019-07-11 04:16:56,495 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.15.217
2019-07-11 04:22:10,533 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 04:24:56,737 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 04:25:48,186 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 153.36.232.36
2019-07-11 04:26:55,278 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 122.195.200.36
2019-07-11 04:27:42,943 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 04:32:53,730 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 134.209.83.125
2019-07-11 04:33:04,367 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 04:34:36,497 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 04:44:13,227 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.110.179
2019-07-11 04:45:57,763 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 122.195.200.148
2019-07-11 04:46:45,852 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 153.36.236.151
2019-07-11 04:46:56,880 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 222.186.15.217
2019-07-11 04:52:10,883 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 04:52:12,902 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 04:52:13,921 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 04:56:33,263 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 04:56:55,806 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 122.195.200.36
2019-07-11 05:01:30,220 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.15.110
2019-07-11 05:02:54,332 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 134.209.83.125
2019-07-11 05:04:36,956 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 05:06:08,073 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 05:07:11,178 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 05:14:13,746 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.110.179
2019-07-11 05:22:13,379 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 05:22:53,432 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 05:22:54,451 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 05:26:33,763 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 05:30:54,115 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 05:31:30,553 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 222.186.15.110
2019-07-11 05:36:08,521 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 05:37:11,622 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 05:37:29,656 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 05:47:24,461 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 05:51:25,090 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 183.131.82.99
2019-07-11 05:52:53,893 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 05:56:46,232 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.110.179
2019-07-11 06:00:54,587 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 06:07:30,059 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 06:08:50,169 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 06:09:18,235 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 06:17:24,850 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 06:19:49,027 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 06:19:50,048 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 06:21:25,427 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 183.131.82.99
2019-07-11 06:26:46,539 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.110.179
2019-07-11 06:31:40,937 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.109.150
2019-07-11 06:31:41,961 fail2ban.actions[13092]: INFO    [asterisk-iptables] 77.247.109.150 already banned
2019-07-11 06:38:01,452 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 06:38:50,616 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 06:39:18,664 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 06:40:30,776 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 06:42:06,022 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 122.195.200.36
2019-07-11 06:44:01,049 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 06:49:49,527 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 07:01:41,422 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.109.150
2019-07-11 07:08:01,902 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 07:10:31,154 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 07:11:08,233 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.232.36
2019-07-11 07:11:53,272 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 07:12:06,312 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 122.195.200.36
2019-07-11 07:14:01,448 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 07:17:13,780 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 07:17:14,800 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 07:18:58,930 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 07:22:36,263 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 07:29:43,577 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.236.35
2019-07-11 07:31:28,737 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.15.28
2019-07-11 07:41:08,463 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 153.36.232.36
2019-07-11 07:41:28,514 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 122.195.200.14
2019-07-11 07:41:53,701 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 07:43:49,866 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 07:47:14,135 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 07:48:59,266 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 07:52:36,556 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 07:57:51,975 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 07:58:43,054 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 07:59:43,910 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 153.36.236.35
2019-07-11 08:01:29,079 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 222.186.15.28
2019-07-11 08:11:28,813 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 122.195.200.14
2019-07-11 08:13:50,193 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 08:15:14,323 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 08:15:34,422 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 08:15:35,443 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 08:27:52,317 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 08:28:43,394 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 08:35:58,951 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 08:38:35,160 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 08:45:14,677 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 08:45:34,716 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 08:46:04,784 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 08:46:05,805 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 08:46:26,827 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 09:05:59,260 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 09:08:35,481 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 09:11:09,704 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 09:16:05,103 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 09:16:27,144 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 09:17:40,246 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 09:30:04,136 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 09:36:23,720 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.110.179
2019-07-11 09:41:10,065 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 09:43:49,255 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 09:43:50,273 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 09:46:07,454 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 09:47:40,598 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 09:49:31,774 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 10:00:04,592 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 10:06:24,149 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.110.179
2019-07-11 10:13:16,683 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.110.179
2019-07-11 10:13:49,737 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 10:16:07,899 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 10:19:32,154 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 10:20:17,224 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 10:21:01,294 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 10:26:47,890 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 10:27:54,041 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 218.92.0.160
2019-07-11 10:41:49,064 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 10:43:17,200 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.110.179
2019-07-11 10:50:17,790 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 10:51:01,864 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 10:52:16,097 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 10:56:48,445 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 10:57:54,359 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 218.92.0.160
2019-07-11 11:05:07,169 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 11:10:46,635 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 11:11:49,746 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 11:22:16,540 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 11:23:56,665 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 11:35:07,548 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 11:39:23,869 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 11:39:24,892 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 11:40:27,968 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 11:40:47,011 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 11:50:27,749 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 11:53:57,003 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 11:55:32,131 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.233.117.109
2019-07-11 11:55:33,843 fail2ban.actions[13092]: WARNING [recidive] Ban 91.233.117.109
2019-07-11 12:09:24,178 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 12:10:24,261 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 12:10:25,278 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 12:10:28,281 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 12:15:15,654 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 12:20:28,044 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 12:25:32,461 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 91.233.117.109
2019-07-11 12:40:24,587 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 12:42:10,749 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.110.179
2019-07-11 12:45:16,028 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 12:51:29,493 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 12:51:33,513 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 12:57:14,949 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 193.201.224.175
2019-07-11 13:07:29,719 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 13:07:30,739 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 13:12:11,113 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.110.179
2019-07-11 13:19:54,705 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.110.179
2019-07-11 13:21:29,843 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 13:21:33,872 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 13:27:01,280 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 46.8.208.36
2019-07-11 13:27:03,583 fail2ban.actions[13092]: WARNING [recidive] Ban 46.8.208.36
2019-07-11 13:27:15,330 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 193.201.224.175
2019-07-11 13:31:30,696 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 13:37:30,163 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 13:37:52,202 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 13:37:53,222 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 13:49:55,121 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.110.179
2019-07-11 13:57:01,675 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 46.8.208.36
2019-07-11 14:01:31,021 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 14:07:52,526 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 14:12:45,921 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 14:16:03,181 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 112.85.42.175
2019-07-11 14:30:38,236 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.109.150
2019-07-11 14:30:39,260 fail2ban.actions[13092]: INFO    [asterisk-iptables] 77.247.109.150 already banned
2019-07-11 14:32:39,417 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 216.245.196.206
2019-07-11 14:34:28,562 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 77.247.110.179
2019-07-11 14:34:39,590 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 14:34:40,611 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 14:42:46,226 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 14:46:03,481 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 112.85.42.175
2019-07-11 15:00:38,632 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.109.150
2019-07-11 15:02:39,784 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 216.245.196.206
2019-07-11 15:04:28,933 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 77.247.110.179
2019-07-11 15:04:39,960 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 64.31.33.70
2019-07-11 15:07:48,220 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 216.245.196.206
2019-07-11 15:13:46,683 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 63.143.35.146
2019-07-11 15:17:04,854 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.232.139
2019-07-11 15:18:23,949 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.15.110
2019-07-11 15:18:27,971 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 122.195.200.36
2019-07-11 15:22:27,268 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.242.143
2019-07-11 15:25:47,555 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.240.126
2019-07-11 15:26:58,802 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 193.201.224.175
2019-07-11 15:33:27,316 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 64.31.33.70
2019-07-11 15:33:28,335 fail2ban.actions[13092]: INFO    [asterisk-iptables] 64.31.33.70 already banned
2019-07-11 15:37:48,670 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 216.245.196.206
2019-07-11 15:40:26,654 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 122.195.200.14
2019-07-11 15:40:37,688 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.52.123
2019-07-11 15:40:54,718 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.236.234
2019-07-11 15:43:29,108 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 216.245.196.206
2019-07-11 15:43:47,146 fail2ban.actions[13092]: WARNING [asterisk-iptables] Unban 63.143.35.146
2019-07-11 15:47:05,236 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 153.36.232.139
---<snip>---
2019-07-11 22:51:00,857 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.52.123
2019-07-11 22:59:09,476 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 222.186.15.28
2019-07-11 23:08:45,180 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 122.195.200.148
2019-07-11 23:11:45,423 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 153.36.236.151
2019-07-11 23:14:52,687 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.15.28
2019-07-11 23:19:34,060 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 122.195.200.36
2019-07-11 23:21:01,184 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 222.186.52.123
2019-07-11 23:38:45,607 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 122.195.200.148
2019-07-11 23:41:13,813 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 218.92.0.193
2019-07-11 23:41:45,866 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 153.36.236.151
2019-07-11 23:44:53,101 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 222.186.15.28
2019-07-11 23:49:39,515 fail2ban.actions[13092]: WARNING [ssh-iptables] Ban 222.186.15.28
2019-07-12 00:11:14,319 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 218.92.0.193
2019-07-12 00:17:39,986 fail2ban.actions[13092]: WARNING [asterisk-iptables] Ban 91.221.67.230
2019-07-12 00:19:39,980 fail2ban.actions[13092]: WARNING [ssh-iptables] Unban 222.186.15.28

#8

Indeed, you (didn’t) lock your self out

cat /var/log/fail2ban.log*|grep "64\.31\.33\.70"

(add it to your ignoreip= in fail2ban until you fix your password :wink: )

sorry bad copy and paste

cat /var/log/fail2ban.log*|grep "162\.255\.22\.40"


(Jared Busch) #9

That is not how it works in FreePBX. Yes we all know you don’t actually do anything with the system. I have no idea why you post here so much.

I’ve already mentioned the correct location to whitelist his network within FreePBX.


#10

I would think of quibbling as we are in the “General Help” forum, any “system” surely means FreePBX itself and not the “Distro”, no ?

But I won’t quibble because it would be just one more post that apparently annoys you :wink: .


(Mark Moore) #11

Can fail2ban be controlled through the FreePBX Console? (A module or Application maybe?)


#12

If you have the ability to install commercial modules, then yes its called sysadmin in the distro, in there the fail2ban ignoreip= is populated by the “whitelist” in the intrusion thingy, but you can do a lot more with fail2ban jails than just protect your voip ports (not in the gooey though) .


(system) closed #13

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.