From mcapetta at sipwise.com Fri Feb 1 05:26:50 2019 From: mcapetta at sipwise.com (Marco Capetta) Date: Fri, 1 Feb 2019 11:26:50 +0100 Subject: [Spce-user] Active calls Message-ID: <7aaaac28-62da-8c1c-405c-45875786ae8c@sipwise.com> Hi Marcos, We found that the issue is related to 'monitoring' module not properly loaded at sems startup. The issue has been already solved and the fix will be available in the upcoming releases: mr6.5.4, mr7.0.2, mr7.1.2, mr7.2.1. Regards Marco -- *Marco Capetta * Operations Engineer Sipwise GmbH , Campus 21/Europaring F15 AT-2345 Brunn am Gebirge Phone: +43(0)1 301 2044 Email: mcapetta at sipwise.com Website: www.sipwise.com Particulars according Austrian Companies Code paragraph 14 "Sipwise GmbH" - Europaring F15 - 2345 Brunn am Gebirge FN:305595f, Commercial Court Vienna, ATU64002206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From henk at voipdigit.nl Sat Feb 2 09:50:48 2019 From: henk at voipdigit.nl (Henk) Date: Sat, 2 Feb 2019 15:50:48 +0100 Subject: [Spce-user] Block sip attacks Message-ID: <266d00f2-6fd1-ba01-a51e-a6f782248f3f@voipdigit.nl> Hi all, I'm using fail2ban and ipset-blocklist to protect my Sipwise system. But lately scanners are not detected by fail2ban anymore, as they are using local or random addresses like this: INVITE sip:0001130046423112923 at 172.31.1.100:5060 SIP/2.0 Via: SIP/2.0/TCP 102.165.36.71:10959;branch=z9hG4bK-524287-1---5918c9179145ae4f;rport Max-Forwards: 70 Contact: ;+sip.instance="" To: From: "1234";tag=a9398072 So only the contact header contains the real IP address. The proxy logs this (other request): Feb? 2 00:01:23 spce proxy[15788]: NOTICE: