Currently, Fail2Ban runs alongside Responsive Firewall to provide additional protection. Since Fail2Ban rules supersede RFW, it is possible that allowed IP's in RFW can still be blocked by Fail2Ban, with no indication in the GUI. Furthermore, a misconfigured device can DoS an entire site that is relying on RFW.
This issue has be debated several times throughout the years on the forums, one example is here:
Responsive Firewall always blocks "good" external users - FreePBX / Security - FreePBX Community Forums
On the one hand, Fail2Ban can provide protection from an attacker with access to the same IP as a registered device, or utilize stolen SIP credentials to further attack a server with no limitations. However, the more common scenario is that a Sysadmin misconfigures a device and this results in a site lockout.