Jump to content

This is the support site for Andrews & Arnold Ltd, a UK Internet provider. Information on these pages is generally for our customers but may be useful to others, enjoy!

VoIP Security: Difference between revisions

Content deleted Content added
Reedy (talk | contribs)
Snom Phones: fix broken link
AA-Andrew (talk | contribs)
 
(10 intermediate revisions by 2 users not shown)
Line 1: Line 1:
<indicator name="VoIP">[[File:menu-voip.svg|link=:Category:VoIP|30px|Back up to the VoIP and SMS Category Page]]</indicator>

This page gives information about features on the AAISP side that can help secure your VoIP service, as well as what you can do on your network to secure your VoIP service.
This page gives information about features on the AAISP side that can help secure your VoIP service, as well as what you can do on your network to secure your VoIP service.


=Security Settings on the AAISP Control Pages=
==Security Settings on the AAISP Control Pages==
These settings are set on the [[:Category:Control Pages|Control Pages]]: http://aa.net.uk/login.html
These settings are set on the [[:Category:Control Pages|Control Pages]]: http://aa.net.uk/login.html


The control page will also show you the number of SIP registrations and the useragent and IP of the registered phones.
The control page will also show you the number of SIP registrations and the useragent and IP of the registered phones.


== SIP Password ==
=== SIP Password ===


*A number will have a sip password, this can be changed from the [[:Category:Control Pages|Control Pages]], the 'Make Password' button will generate a password for you.
*A number will have a sip password, this can be changed from the [[:Category:Control Pages|Control Pages]], the 'Make Password' button will generate a password for you.
*You can remove the password so as to prevent calls being made and telephones from registering.
Ensure you use a VERY strong password.


== Call Rate Limits ==
=== Call Rate Limits ===


*National outgoing calls can have a price limit (default = 20p/min)
*National outgoing calls can have a price limit (default = 20p/min)
*International outgoing calls can have a price limit (default = 2p/min)
*International outgoing calls can have a price limit (default = 2p/min)
You can lower these, or set to zero to prevent charged calls from being made. To increase the rate, please email Support.


See: [[VoIP Call Rate Limits]]
See: [[VoIP Call Rate Limits]]


== IP Allow List (restrict access by IP) ==
=== IP Access List (restrict access by IP) ===


IP Lockdown - a VoIP number can be given an IP address to which is only allowed to register (i.e. you can add the IP of your phone, and only that phone will be able to register)
IP Access List - a VoIP number can be given an IP address to which is only allowed to register (i.e. Your WAN IP, issued by your ISP)


You can specify the IP as a subnet in CIDR format, e.g. 192.0.2.0/29, and multiple IPs can be comma separated.
[[File:ControlPages-VoIP-IPLockdown.png|none|frame|IP Lockdown, comma separated etc.]]

On the Voiceless platform you can specify the IP as a subnet in CIDR format, e.g. 192.0.2.0/29, and multiple IPs can be comma separated.


Valid examples:
Valid examples:
Line 34: Line 37:
2001:DB8::/48, 128.66.0.0/27 (a IPv6 and an IPv4 network block)
2001:DB8::/48, 128.66.0.0/27 (a IPv6 and an IPv4 network block)


== Bill Warning Emails ==
=== Bill Warning Emails ===
The system can send advisory messages when a billing amount is reached. This is set per number on the [[:Category:Control Pages|Control Pages]]. The email set for the Number and for the Login is used.
The system can send advisory messages when a billing amount is reached. This is set per number on the [[:Category:Control Pages|Control Pages]]. The email set for the Number and for the Login is used.
During the month, each time the amount is reached an email will be sent. At the end of the month the amount is reset.
During the month, each time the amount is reached an email will be sent. At the end of the month the amount is reset.
This feature was added in October 2011, the default warning level is £10, and for numbers which used over £10 in September the rate was set to 1.2 times September's bill amount.


The default warning level is £10.
== IP and User Agent Warning Emails ==

=== IP and User Agent Warning Emails ===
A new feature added [http://status.aa.net.uk/1948 2014-06-11]
A new feature added [http://status.aa.net.uk/1948 2014-06-11]


Line 59: Line 63:
*We email the email address as set on the individual phone number. If the email address is not set then an email won't be sent.
*We email the email address as set on the individual phone number. If the email address is not set then an email won't be sent.


=Secure Your Equipment=
==Secure Your Equipment==


== Your Firewall ==
=== Your Firewall ===


Protect your phones and VoIP servers from the outside world!
Protect your phones and VoIP servers from the outside world!
Line 67: Line 71:
*See [[VoIP Firewall]] for firewall requirements.
*See [[VoIP Firewall]] for firewall requirements.


==Passwords, etc.==
===Passwords, etc.===


Many Phone systems and VoIP phones will have their own security features, do make use of them and use strong passwords. See your equipment documentation for further information.
Many Phone systems and VoIP phones will have their own security features, do make use of them and use strong passwords. See your equipment documentation for further information.
Line 75: Line 79:
*Periodically check for software/firmware updates for your hardware
*Periodically check for software/firmware updates for your hardware


==Keep the Software/Firmware updated==
===Keep the Software/Firmware updated===
Regularly checking for software updates is strongly recommended. e.g., check the website of the phone manufacturer for updates.
Regularly checking for software updates is strongly recommended. e.g., check the website of the phone manufacturer for updates.
*[[SNOM Firmware Updates]]
*[[SNOM Firmware Updates]]