My understanding is that, unlike previously with just fail2ban, if wrong credentials are used while registering, but other devices are already registered from that public IP, it will only ban that extension but not the whole public IP address. If however there is nothing yet connected from that IP, it will ban the public ip altogether.
This does not seem to apply when a wrong subscribe message comes through. I had a customer who kept on getting their public IP address banned despite many devices being registered. The cause was a wrongly configured phone with a subscribe message that contained a wrong domain name. As a result their whole office kept going down.
Question 1 - is it doable to change this behaviour do that it does not ban a whole office if one phone is wrongly configured
Question 2 - would it be possible to have a whitelist feature in the GUI, preferably with a time frame. Something like "whitelist this ip for 1 hour" so that support staff can avoid the client being banned while the client figures out the issue. The timeframe is important as invariably it would be forgotten about and left there in the whitelist.
This does not seem to apply when a wrong subscribe message comes through. I had a customer who kept on getting their public IP address banned despite many devices being registered. The cause was a wrongly configured phone with a subscribe message that contained a wrong domain name. As a result their whole office kept going down.
Question 1 - is it doable to change this behaviour do that it does not ban a whole office if one phone is wrongly configured
Question 2 - would it be possible to have a whitelist feature in the GUI, preferably with a time frame. Something like "whitelist this ip for 1 hour" so that support staff can avoid the client being banned while the client figures out the issue. The timeframe is important as invariably it would be forgotten about and left there in the whitelist.