Just heads up to people deploying fail2ban in order to improve the security of asterisk installs.
This tool is rather useless currently. It only bans IPs who try to register. Most people define their SIP devices/peers as type=friend which means registration is not necessary to initiate calls. Anyone with access to SIP port can send an INVITE and start cracking passwords. More info: viewtopic.php?t=78538
The problem number one is people using type=friend based on an incorrect info from the various online/offline sources including digium’s own.
Problem number two is asterisk does not log enough info for fail2ban to detect anything.
Adding additional regexes to mach will not help without changes in asterisk core.
Update: The problem has already been discussed in these threads: