Herman, have you investigated the banbrutes.php script that comes with Yate? That is exactly what it does -- uses iptables to block flooding / brute force attacks.

If you do not like the way it works, you can use the concepts within to redesign it for your own needs, even to feed fail2ban. It was written very clearly. (By Paul I think - thank you Paul!)

On Aug 3, 2013, at 2:08 AM, Herman Bigos wrote:

> Diana,
> but I would like to log unauthorized events like to block them by fail2ban. So i need to know IP address of sniffer which attack my server of mass INVITE's with wrong username ?
> I know that Yate has his own antihacking but I would like to use iptables because it is on lower level.
> Regards
> Herman

