by williamconley » Fri Mar 15, 2013 2:05 pm
Which is why we use IP whitelisting instead of fail2ban. Fail2ban will not stop a DOS attack, as it has to "get" the packets before dropping them. It will slow down a brute force, or require that the attacker rotate IPs, but will not stop a brute force from becoming a DOS attack if the attacker is unaware that fail2ban has locked them out. They may continue to send packets and lock up your server even though fail2ban is dropping the packets.
Whitelist, on the other hand, does not Ever respond to the attacker. They never find out Asterisk (or ssh, or any other process) is running on the server. So ... nothing to attack. A pure whitelist system will even make it appear that there is No Server present. An even better "nothing to attack" scenario.
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294