AiPBX incorporates multi-tier defense mechanisms against brute-force VoIP scanners and packet sniffers. It also features Microsoft Teams Direct Routing integration for seamless enterprise unified communications.
1. Defense-in-Depth Architecture
| Security Tier | Enforced Policy | Mitigated Threat |
|---|---|---|
| Edge L4 Stream | Nginx L4 Stream + ALPN Inspection | Minimizes attack surface by tunneling over port 443; drops unauthorized probes. |
| Transport Encryption | TLS 1.3, DTLS-SRTP, SDES-SRTP, TURNS | Prevents audio eavesdropping and credential sniffing across public networks. |
| Rate Limiting & Jails | Fail2ban PBX Jails + Nginx Leaky Bucket | Instantly bans SIP brute-force bots and aggressive scanners (sipvicious). |
2. Fail2ban PBX Jails & Automated Banning
/etc/fail2ban/jail.d/asterisk.conf
[asterisk-pjsip]
enabled = true
filter = asterisk-pjsip
action = iptables-allports[name=ASTERISK, protocol=all]
logpath = /var/log/asterisk/messages
maxretry = 5
findtime = 600
bantime = 86400