Fred Posner writes:
On a targeted attack, APIBAN won’t help. You will see some benefits from iptables-api which will block your discovered traffic in iptables and helping reduce kamailio cpu.
I'm blocking attacks by fail2ban. My APIBAN test would generate syslog message for fail2ban, but none has been generated. It means that among the numerous attacks that my SIP proxy blocked by fail2ban, not a single one was detected by APIBAN. It means that APIBAN was not aware of the IP addresses of the attackers.
-- Juha