No es por firewall de issabelpbx.
Esta sol las reglas que tengo actualmente, ojo con geoip que esta bloqueados todos los países menos España.
Iptables –new-chain ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags ALL NONE -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags FIN,RST FIN,RST -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags ACK,FIN FIN -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags ACK,PSH PSH -j ANTIRASTREO
Iptables -A INPUT -p tcp --tcp-flags ACK,URG URG -j ANTIRASTREO
iptables -A ANTIRASTREO -j LOG --log-prefix "firewall-antirastreo: " --log-level 6
iptables -A ANTIRASTREO -j DROP
iptables --new-chain SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CN,GB,DE,FR,US,RU,ID,NL,LT,AL,VN,BG,CA,SC,US -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc AO,BF,BI,BJ,BW,CD,CF,CG,CI,CM -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CV,DJ,DZ,EG,ER,ET,GA,GH,GM,GN -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc GQ,GW,KE,KM,LR,LS,LY,MA,MG,ML -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc MR,MU,MW,MZ,NA,NE,NG,RE,RW,SC -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc SD,SH,SL,SN,SO,ST,SZ,TD,TG,TN -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc TZ,UG,YT,ZA,ZM,ZW,AQ,GS,TF,AE -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc AF,AM,AZ,BD,BH,BN,BT,CC,CN,CX -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CY,GE,HK,ID,IL,IN,IO,IQ,IR,JO -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc JP,KG,KH,KP,KR,KW,KZ,LA,LB,LK -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc MM,MN,MO,MV,MY,NP,OM,PH,PK,PS -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc QA,SA,SG,SY,TH,TJ,TL,TM,TR,TW -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc UZ,VN,YE,AD,AL,AT,AX,BA,BE,BG -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc BY,CH,CZ,DE,DK,EE,FI,FO,FR -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc GB,GG,GI,GR,HR,HU,IE,IM,IS,IT -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc JE,LI,LT,LU,LV,MC,MD,ME,MK,MT -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc NL,NO,PL,PT,RO,RS,RU,SE,SI,SJ -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc SK,SM,UA,VA,AG,AI,AW,BB,BL,BM -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc BS,BZ,CA,CR,CU,DM,DO,GD,GL,GP -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc GT,HN,HT,JM,KN,KY,LC,MF,MQ,MS -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc MX,NI,PA,PM,PR,SV,TC,TT,US,VC -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc VG,AS,AU,CK,FJ,FM,GU,KI,MH,MP -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc NC,NF,NR,NU,NZ,PF,PG,PN,PW,SB -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc TK,TO,TV,UM,VU,WF,WS,AR,BO,BR -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CL,CO,EC,FK,GF,GY,PE,PY,SR,UY -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CN,GB,DE,FR,US,RU,ID,NL,LT,AL,VN,BG,CA,SC,US -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc AO,BF,BI,BJ,BW,CD,CF,CG,CI,CM -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CV,DJ,DZ,EG,ER,ET,GA,GH,GM,GN -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc GQ,GW,KE,KM,LR,LS,LY,MA,MG,ML -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc MR,MU,MW,MZ,NA,NE,NG,RE,RW,SC -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc SD,SH,SL,SN,SO,ST,SZ,TD,TG,TN -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc TZ,UG,YT,ZA,ZM,ZW,AQ,GS,TF,AE -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc AF,AM,AZ,BD,BH,BN,BT,CC,CN,CX -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CY,GE,HK,ID,IL,IN,IO,IQ,IR,JO -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc JP,KG,KH,KP,KR,KW,KZ,LA,LB,LK -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc MM,MN,MO,MV,MY,NP,OM,PH,PK,PS -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc QA,SA,SG,SY,TH,TJ,TL,TM,TR,TW -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc UZ,VN,YE,AD,AL,AT,AX,BA,BE,BG -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc BY,CH,CZ,DE,DK,EE,FI,FO,FR -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc GB,GG,GI,GR,HR,HU,IE,IM,IS,IT -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc JE,LI,LT,LU,LV,MC,MD,ME,MK,MT -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc NL,NO,PL,PT,RO,RS,RU,SE,SI,SJ -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc SK,SM,UA,VA,AG,AI,AW,BB,BL,BM -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc BS,BZ,CA,CR,CU,DM,DO,GD,GL,GP -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc GT,HN,HT,JM,KN,KY,LC,MF,MQ,MS -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc MX,NI,PA,PM,PR,SV,TC,TT,US,VC -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc VG,AS,AU,CK,FJ,FM,GU,KI,MH,MP -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc NC,NF,NR,NU,NZ,PF,PG,PN,PW,SB -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc TK,TO,TV,UM,VU,WF,WS,AR,BO,BR -j SIPGEOIP
iptables -A INPUT -p udp -m udp -m multiport --dports 5060:5082,80,443,22,10000:20000 -m geoip --src-cc CL,CO,EC,FK,GF,GY,PE,PY,SR,UY -j SIPGEOIP
iptables -A INPUT -p tcp -m tcp -m multiport --dports 80,443 -m geoip --src-cc A1 -j SIPGEOIP
iptables -A SIPGEOIP -j LOG --log-prefix "firewall-sipgeoip: " --log-level 6
iptables -A SIPGEOIP -j DROP
iptables --new-chain SIPDDOS
#User-Agent: sipcli/v1.8
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sundayddr" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "sundayddr" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sipsak" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "sipsak" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sipvicious" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sipvicious " --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "friendly-scanner" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "friendly-scanner" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "iWar" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "iWar" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sip-scan" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "sip-scan" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sipcli" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "sipcli" --algo bm -j SIPDDOS
#iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "eyeBeam" --algo bm -j SIPDDOS
#iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "eyeBeam" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "pjsip python" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "pjsip python" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "Custom SIP Phone" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "Custom SIP Phone" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "VaxSIPUserAgent" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "VaxSIPUserAgent" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sip:nm@nm" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "sip:nm@nm" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --dport 5060:5082 -m string --string "sip:carol@chicago.com" --algo bm -j SIPDDOS
iptables -A INPUT -p tcp --sport 5060:5082 -m string --string "sip:carol@chicago.com" --algo bm -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sundayddr" --algo bm --to 65535 -m comment --comment "deny sundayddr" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sundayddr" --algo bm --to 65535 -m comment --comment "deny sundayddr" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sipsak" --algo bm --to 65535 -m comment --comment "deny sipsak" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sipsak" --algo bm --to 65535 -m comment --comment "deny sipsak" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sipvicious" --algo bm --to 65535 -m comment --comment "deny sipvicious" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sipvicious" --algo bm --to 65535 -m comment --comment "deny sipvicious" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "friendly-scanner" --algo bm --to 65535 -m comment --comment "deny friendly-scanner" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "friendly-scanner" --algo bm --to 65535 -m comment --comment "deny friendly-scanner" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "iWar" --algo bm --to 65535 -m comment --comment "deny iWar" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "iWar" --algo bm --to 65535 -m comment --comment "deny iWar" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sip-scan" --algo bm --to 65535 -m comment --comment "sip-scan" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sip-scan" --algo bm --to 65535 -m comment --comment "sip-scan" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sipcli" --algo bm --to 65535 -m comment --comment "deny sip-scan" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sipcli" --algo bm --to 65535 -m comment --comment "deny sip-scan" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sipcli/v1.8" --algo bm --to 65535 -m comment --comment "deny sip-scan" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sipcli/v1.8" --algo bm --to 65535 -m comment --comment "deny sip-scan" -j SIPDDOS
#iptables -A INPUT -p udp --sport 5060:5082 -m string --string "eyeBeam" --algo bm --to 65535 -m comment --comment "deny eyeBeam" -j SIPDDOS
#iptables -A INPUT -p udp --dport 5060:5082 -m string --string "eyeBeam" --algo bm --to 65535 -m comment --comment "deny eyeBeam" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "pjsip python" --algo bm --to 65535 -m comment --comment "deny pjsip python" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "pjsip python" --algo bm --to 65535 -m comment --comment "deny pjsip python" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "Custom SIP Phone" --algo bm --to 65535 -m comment --comment "deny Custom SIP Phone" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "Custom SIP Phone" --algo bm --to 65535 -m comment --comment "deny Custom SIP Phone" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "VaxSIPUserAgent" --algo bm --to 65535 -m comment --comment "deny VaxSIPUserAgent" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "VaxSIPUserAgent" --algo bm --to 65535 -m comment --comment "deny VaxSIPUserAgent" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sip:nm@nm" --algo bm --to 65535 -m comment --comment "deny sip:nm@nm" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sip:nm@nm" --algo bm --to 65535 -m comment --comment "deny sip:nm@nm" -j SIPDDOS
iptables -A INPUT -p udp --sport 5060:5082 -m string --string "sip:carol@chicago.com" --algo bm --to 65535 -m comment --comment "deny sip:nm@nm" -j SIPDDOS
iptables -A INPUT -p udp --dport 5060:5082 -m string --string "sip:carol@chicago.com" --algo bm --to 65535 -m comment --comment "deny sip:nm@nm" -j SIPDDOS
iptables -A SIPDDOS -j LOG --log-prefix "firewall-sipddos: " --log-level 6
iptables -A SIPDDOS -j DROP