Intrusion detection blocking Digium(PRI to SIP)?

So we have a PRI that is going to a Digium gateway device. For some reason it started getting blocked by intrusion detection (fail2ban).

Anyone have any ideas why this would happen? For now, I put the device in the whitelist but not sure why it was being banned in the first place.

In the logs we see this appearing: [2015-11-27 13:21:54] WARNING[4127][C-0000005e] Ext. s: Friendly Scanner from (this is always the IP of the Digium gateway)

[2015-11-27 13:29:16] VERBOSE[4402][C-0000007d] pbx.c: – Executing [[email protected]:3] Log(“SIP/7715-00000087”, “WARNING,Friendly Scanner from 10.10.40.18”) in new stack
[2015-11-27 13:29:16] WARNING[4402][C-0000007d] Ext. s: Friendly Scanner from 10.10.40.18

Any ideas??

Found out it was a SIPVicious attack if anyone else has this issue.

Thanks for all the input. :smiley: