Is there an easy way to deny an IP across multiple realms?
Lately I have been seeing SIP registration scanning attempts that are not triggering my configured DDoS settings. As an example I will see one source IP send a register to a public IP over the Internet realm that is configured for allow-anonymous registered. The source IP will have a list of several hundred users and it will just send one register and get back the 403 because it is trying to guess the password. The next register it will change the source port and user and try again, only doing one try then changing the source port and username. This