Help sorting out what is happening with the firewall

New installation - freepbx latest with Asterisk 13 behind a nat firewall with the relevant ports forwarded to the FreePBX install with its “progressive and active firewall”

i see

[2016-12-13 22:08:05] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"1001" <sip:[email protected]>' failed for '23.239.84.211:5071' (callid: e2f1d6747a6a59030ad53574dc72648a) - Failed to authenticate

a lot in my full log… but

grep 23.239.84.211 /var/log/asterisk/full -c
3879

means that this pesky IP has had 3879 attempts at abusing me (today) - i assumed that the adaptive and progressive firewall would have blocked it by now - i CAN do this with fail2ban or Ossec (which i have active on the machine) but i would like the firewall blocking this kind of stuff…

SHOULD it be blocking 3879 tries to do this?

[2016-12-13 22:17:25] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"201" <sip:[email protected]>' failed for '23.239.84.211:5101' (callid: 2b9d1509e9fd58e7ae76ed1cb3559465) - Failed to authenticate
[2016-12-13 22:17:26] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"201" <sip:[email protected]>' failed for '23.239.84.211:5101' (callid: 2b9d1509e9fd58e7ae76ed1cb3559465) - No matching endpoint found
[2016-12-13 22:17:26] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"201" <sip:[email protected]>' failed for '23.239.84.211:5101' (callid: 2b9d1509e9fd58e7ae76ed1cb3559465) - Failed to authenticate
[2016-12-13 22:17:26] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"201" <sip:[email protected]>' failed for '23.239.84.211:5101' (callid: 2b9d1509e9fd58e7ae76ed1cb3559465) - No matching endpoint found
[2016-12-13 22:17:26] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"201" <sip:[email protected]>' failed for '23.239.84.211:5101' (callid: 2b9d1509e9fd58e7ae76ed1cb3559465) - Failed to authenticate
[2016-12-13 22:17:26] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"201" <sip:[email protected]>' failed for '23.239.84.211:5101' (callid: 2b9d1509e9fd58e7ae76ed1cb3559465) - No matching endpoint found
[2016-12-13 22:17:26] NOTICE[19447]: res_pjsip/pjsip_distributor.c:525 log_failed_request: Request 'INVITE' from '"201" <sip:[email protected]>' failed for '23.239.84.211:5101' (callid: 2b9d1509e9fd58e7ae76ed1cb3559465) - Failed to authenticate

for now - i will close the sip port off again… but any pointers to this would be helpful - in the past my stupid passwords have gotten me into being a proxy for some calls to strangers far away - which i really don’t want to happen again.