Problem on non-critical invite
Posted: Mon Jul 20, 2020 7:44 am
Hi guys, I'm having a lot of warning message like this
WARNING[2354]: chan_sip.c:4128 retrans_pkt: Timeout on 936484740-1667659206-1445942090 on non-critical invite transaction.
so i turned on the sip debug and I got an ip address and a non existing phone (46.105.113.12 and 7085).
I already setup fail2ban and it is working and I whitelisted my ipaddress and my carrier ipaddress but this ip address 46.105.113.12 always shows up and it show the warning message. What I did is I manually ban the ipaddress 46.105.113.12 and it fixed the problem. How can I automatically block this by using fail2ban? Why fail2ban doesn't detect this? and what 46.105.113.12 is doing to my server? is like connecting it self?
I am new to asterisk and when it comes to debugging. Please help me. Thank you.
(11 headers 10 lines) ---
[Jul 20 05:30:50] Sending to 46.105.113.12:61166 (NAT)
[Jul 20 05:30:50] Sending to 46.105.113.12:61166 (NAT)
[Jul 20 05:30:50] Using INVITE request as basis request - 936484740-1667659206-1445942090
[Jul 20 05:30:50] No matching peer for '7085' from '46.105.113.12:61166'
[Jul 20 05:30:50]
[Jul 20 05:30:50] <--- Reliably Transmitting (NAT) to 46.105.113.12:61166 --->
[Jul 20 05:30:50] SIP/2.0 401 Unauthorized
[Jul 20 05:30:50] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:50] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:50] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:50] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:50] CSeq: 1 INVITE
[Jul 20 05:30:50] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:50] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:50] Supported: replaces, timer
[Jul 20 05:30:50] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:50] Content-Length: 0
[Jul 20 05:30:50]
[Jul 20 05:30:50]
[Jul 20 05:30:50] <------------>
[Jul 20 05:30:50] Scheduling destruction of SIP dialog '936484740-1667659206-1445942090' in 32000 ms (Method: INVITE)
[Jul 20 05:30:51] Retransmitting #1 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:51] SIP/2.0 401 Unauthorized
[Jul 20 05:30:51] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:51] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:51] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:51] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:51] CSeq: 1 INVITE
[Jul 20 05:30:51] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:51] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:51] Supported: replaces, timer
[Jul 20 05:30:51] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:51] Content-Length: 0
[Jul 20 05:30:51]
[Jul 20 05:30:51]
[Jul 20 05:30:51] ---
[Jul 20 05:30:52] Retransmitting #2 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:52] SIP/2.0 401 Unauthorized
[Jul 20 05:30:52] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:52] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:52] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:52] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:52] CSeq: 1 INVITE
[Jul 20 05:30:52] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:52] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:52] Supported: replaces, timer
[Jul 20 05:30:52] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:52] Content-Length: 0
[Jul 20 05:30:52]
[Jul 20 05:30:52]
[Jul 20 05:30:52] ---
[Jul 20 05:30:54] Retransmitting #3 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:54] SIP/2.0 401 Unauthorized
[Jul 20 05:30:54] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:54] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:54] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:54] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:54] CSeq: 1 INVITE
[Jul 20 05:30:54] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:54] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:54] Supported: replaces, timer
[Jul 20 05:30:54] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:54] Content-Length: 0
[Jul 20 05:30:54]
[Jul 20 05:30:54]
[Jul 20 05:30:54] ---
[Jul 20 05:30:58] Retransmitting #4 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:58] SIP/2.0 401 Unauthorized
[Jul 20 05:30:58] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:58] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:58] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:58] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:58] CSeq: 1 INVITE
[Jul 20 05:30:58] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:58] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:58] Supported: replaces, timer
[Jul 20 05:30:58] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:58] Content-Length: 0
[Jul 20 05:30:58]
[Jul 20 05:30:58]
[Jul 20 05:30:58] ---
[Jul 20 05:31:01] == Manager 'sendcron' logged on from 127.0.0.1
[Jul 20 05:31:01] == Manager 'sendcron' logged on from 127.0.0.1
[Jul 20 05:31:01] == Manager 'sendcron' logged off from 127.0.0.1
[Jul 20 05:31:02] Retransmitting #5 (NAT) to 46.105.113.12:61166:
[Jul 20 05:31:02] SIP/2.0 401 Unauthorized
[Jul 20 05:31:02] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:31:02] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:31:02] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:31:02] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:31:02] CSeq: 1 INVITE
[Jul 20 05:31:02] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:31:02] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:31:02] Supported: replaces, timer
[Jul 20 05:31:02] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:31:02] Content-Length: 0
Cluster setup
ViciBox v.8.1.2 ISO
VERSION: 2.14-733a
BUILD: 200115-1702
Asterisk 13.29.2-vici
WARNING[2354]: chan_sip.c:4128 retrans_pkt: Timeout on 936484740-1667659206-1445942090 on non-critical invite transaction.
so i turned on the sip debug and I got an ip address and a non existing phone (46.105.113.12 and 7085).
I already setup fail2ban and it is working and I whitelisted my ipaddress and my carrier ipaddress but this ip address 46.105.113.12 always shows up and it show the warning message. What I did is I manually ban the ipaddress 46.105.113.12 and it fixed the problem. How can I automatically block this by using fail2ban? Why fail2ban doesn't detect this? and what 46.105.113.12 is doing to my server? is like connecting it self?
I am new to asterisk and when it comes to debugging. Please help me. Thank you.
(11 headers 10 lines) ---
[Jul 20 05:30:50] Sending to 46.105.113.12:61166 (NAT)
[Jul 20 05:30:50] Sending to 46.105.113.12:61166 (NAT)
[Jul 20 05:30:50] Using INVITE request as basis request - 936484740-1667659206-1445942090
[Jul 20 05:30:50] No matching peer for '7085' from '46.105.113.12:61166'
[Jul 20 05:30:50]
[Jul 20 05:30:50] <--- Reliably Transmitting (NAT) to 46.105.113.12:61166 --->
[Jul 20 05:30:50] SIP/2.0 401 Unauthorized
[Jul 20 05:30:50] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:50] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:50] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:50] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:50] CSeq: 1 INVITE
[Jul 20 05:30:50] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:50] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:50] Supported: replaces, timer
[Jul 20 05:30:50] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:50] Content-Length: 0
[Jul 20 05:30:50]
[Jul 20 05:30:50]
[Jul 20 05:30:50] <------------>
[Jul 20 05:30:50] Scheduling destruction of SIP dialog '936484740-1667659206-1445942090' in 32000 ms (Method: INVITE)
[Jul 20 05:30:51] Retransmitting #1 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:51] SIP/2.0 401 Unauthorized
[Jul 20 05:30:51] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:51] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:51] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:51] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:51] CSeq: 1 INVITE
[Jul 20 05:30:51] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:51] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:51] Supported: replaces, timer
[Jul 20 05:30:51] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:51] Content-Length: 0
[Jul 20 05:30:51]
[Jul 20 05:30:51]
[Jul 20 05:30:51] ---
[Jul 20 05:30:52] Retransmitting #2 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:52] SIP/2.0 401 Unauthorized
[Jul 20 05:30:52] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:52] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:52] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:52] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:52] CSeq: 1 INVITE
[Jul 20 05:30:52] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:52] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:52] Supported: replaces, timer
[Jul 20 05:30:52] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:52] Content-Length: 0
[Jul 20 05:30:52]
[Jul 20 05:30:52]
[Jul 20 05:30:52] ---
[Jul 20 05:30:54] Retransmitting #3 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:54] SIP/2.0 401 Unauthorized
[Jul 20 05:30:54] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:54] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:54] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:54] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:54] CSeq: 1 INVITE
[Jul 20 05:30:54] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:54] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:54] Supported: replaces, timer
[Jul 20 05:30:54] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:54] Content-Length: 0
[Jul 20 05:30:54]
[Jul 20 05:30:54]
[Jul 20 05:30:54] ---
[Jul 20 05:30:58] Retransmitting #4 (NAT) to 46.105.113.12:61166:
[Jul 20 05:30:58] SIP/2.0 401 Unauthorized
[Jul 20 05:30:58] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:30:58] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:30:58] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:30:58] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:30:58] CSeq: 1 INVITE
[Jul 20 05:30:58] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:30:58] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:30:58] Supported: replaces, timer
[Jul 20 05:30:58] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:30:58] Content-Length: 0
[Jul 20 05:30:58]
[Jul 20 05:30:58]
[Jul 20 05:30:58] ---
[Jul 20 05:31:01] == Manager 'sendcron' logged on from 127.0.0.1
[Jul 20 05:31:01] == Manager 'sendcron' logged on from 127.0.0.1
[Jul 20 05:31:01] == Manager 'sendcron' logged off from 127.0.0.1
[Jul 20 05:31:02] Retransmitting #5 (NAT) to 46.105.113.12:61166:
[Jul 20 05:31:02] SIP/2.0 401 Unauthorized
[Jul 20 05:31:02] Via: SIP/2.0/UDP 46.105.113.12:61166;branch=z9hG4bK337232991;received=46.105.113.12;rport=61166
[Jul 20 05:31:02] From: <sip:7085@my.ip.address.xx>;tag=1866032968
[Jul 20 05:31:02] To: <sip:+441519470494@my.ip.address.xx>;tag=as49f662e9
[Jul 20 05:31:02] Call-ID: 936484740-1667659206-1445942090
[Jul 20 05:31:02] CSeq: 1 INVITE
[Jul 20 05:31:02] Server: Asterisk PBX 13.29.2-vici
[Jul 20 05:31:02] Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE
[Jul 20 05:31:02] Supported: replaces, timer
[Jul 20 05:31:02] WWW-Authenticate: Digest algorithm=MD5, realm="asterisk", nonce="39c34c3a"
[Jul 20 05:31:02] Content-Length: 0
Cluster setup
ViciBox v.8.1.2 ISO
VERSION: 2.14-733a
BUILD: 200115-1702
Asterisk 13.29.2-vici