Temporarily Banned IPs
This section shows the IP addresses the system has temporarily banned, along with the reason for and the time of each ban. Automatic banning is a front-line defense against the constant background of attacks that any Internet-facing PBX attracts - password-guessing and SIP scanning that, unchecked, can lock out accounts, run up toll fraud, or degrade service. IPs are banned automatically due to multiple authentication failures or by Traffic Spike Control, so most of the time this screen requires no action; it is here for when you need to review or reverse a ban.
Unbanning IP Addresses
You can “unban” the selected IPs by deleting them from the list by clicking “Delete Selected”, or both delete the IPs from the list and permanently add to the list of Trusted IPs by clicking “Unban and Add to Trusted IPs”.
Best practices
- Only add an address to Trusted IPs when you are certain it is safe (for example a known office or carrier). A trusted IP bypasses the automatic protections, so a mistake here permanently opens a hole.
- Investigate before you unban. A repeated ban on the same address often means a genuine attack or a misconfigured device that keeps sending bad credentials - unbanning without fixing the cause just invites the next ban.
- Prefer whitelisting a fixed office IP over disabling protection. If staff keep getting banned, add their static address to Trusted IPs rather than loosening Traffic Spike Control.
Related documentation
- Trusted IPs - addresses exempt from automatic banning
- Traffic Spike Control - what triggers automatic bans