User's Manual Part 1
Firmware Version 1.0.0.1  UCM6200 Series IP PBX User Manual  Page 63 of 320
  Since IP address 192.168.40.5 is in whitelist, if the host at IP address 192.168.40.5 initiates more than 
20 TCP connections to the UCM6200 within 1 minute, it will not be added into UCM6200 blacklist. It 
can still establish TCP connection with the UCM6200. 
Figure 34: Configure Dynamic Defense 
FAIL2BAN
Fail2Ban feature on the UCM6200 provides intrusion detection and prevention for authentication errors in 
SIP REGISTER, INVITE and SUBSCRIBE. Once the entry is detected within "Max Retry Duration", the 
UCM6200 will take action to forbid the host for certain period as defined in "Banned Duration". This feature 
helps prevent SIP brute force attacks to the PBX system. 
Table 18: Fail2Ban Settings 
Global Settings 
Enable Fail2Ban 
Enable Fail2Ban. The default setting is disabled. Please make sure both "Enable 
Fail2Ban" and "Asterisk Service" are turned on in order to use Fail2Ban for SIP 
authentication on the UCM6200. 
Banned Duration 
Configure the duration (in seconds) for the detected host to be banned. The 
default setting is 300. If set to -1, the host will be always banned. 
Max Retry Duration 
Within this duration (in seconds), if a host exceeds the max times of retry as 
defined in "MaxRetry", the host will be banned. The default setting is 5. 
MaxRetry 
Configure the number of authentication failures during "Max Retry Duration" 
before the host is banned. The default setting is 10. 
Fail2Ban Whitelist 
Configure IP address, CIDR mask or DNS host in the whiltelist. Fail2Ban will not 










