You clearly stated fail2ban actions not iptables actions. They are not the same thing.
@scottalanmiller said in Fanvil possible firmware issue, non-standard port:
We've seen that kill fail2ban so that it ties up so many CPU cycles that performance drops.
That said, managing iptbales would be the admin's job. Monitoring the bans and jsut blocking entire CIDR would be a normal need.
Preemptive IP blacklisting is also a normal, intelligent thing to do. By geo, common known CIDR, etc.
There is zero reason to leave any PBX system, for a typical American SMB, open to the entire planet by default.