Can you please post the rules used? I have spent couple of days, having studied a subject and other branches of a forum, haven't found the ready solution, have as a result made itself thus. Rules for blocking of SIP brute force activity. /ip firewall filter add action=drop chain=input comment="...