I cant find much information about AFP either. From what I have seen it just seems to be intended to an easier way to configure the firewall.
Personally I would stick to the standard iptables that everyone else uses as you will get much better support from the community by using it.
For details of setting up fail2ban with iptables and Asterisk see
http://www.voip-info.org/wiki/view/Fail2Ban+%28with+iptables%29+And+Asterisk