- Joined
- Jun 17, 2015
- Messages
- 84
- Reaction score
- 21
I have an issue with our SIP provider where our blacklist feature blocks their IP every 30 days when the allow entry I've built expires. We've only been on this SIP provider for a couple of months so this is the 2nd time it's happened. Our SIP provider uses IP only with no authentication configured. I've contacted my SIP providers NOC and they're trying to figure out what our options are as they believe there is no authentication attempts occurring. They did a few test calls with packet captures so I'm hoping they find something wrong on their end.
I figured out how to extend our allow entry past 30 days. The UI is a little weird and you have to configure it as a Deny entry in order for the date fields to appear. Once you switch the entry back to Allow the date fields disappear but they still apply.
My question is this; how many auth attempts are necessary for the blacklist feature to block an IP? And how do I pull this information out of the system? I'm not seeing the failed auth attempts anywhere in the logs. A while back I set my debugging verbosity higher so I can use the log viewer for the files from "Generate Support Info" and I'm just not seeing anything.
I figured out how to extend our allow entry past 30 days. The UI is a little weird and you have to configure it as a Deny entry in order for the date fields to appear. Once you switch the entry back to Allow the date fields disappear but they still apply.
My question is this; how many auth attempts are necessary for the blacklist feature to block an IP? And how do I pull this information out of the system? I'm not seeing the failed auth attempts anywhere in the logs. A while back I set my debugging verbosity higher so I can use the log viewer for the files from "Generate Support Info" and I'm just not seeing anything.