Jump to content

This is the support site for Andrews & Arnold Ltd, a UK Internet provider. Information on these pages is generally for our customers but may be useful to others, enjoy!

VoIP Security: Difference between revisions

m
clean up, typos fixed: ie → i.e. (2), etc] → etc.], eg → e.g. (2), a IPv4 → an IPv4 (2)
m (clean up, typos fixed: ie → i.e. (2), etc] → etc.], eg → e.g. (2), a IPv4 → an IPv4 (2))
[[fileFile:Snom710.png|link=:Category:VoIP|Go to the VoIP Category]]
 
This page gives information about features on the AAISP side that can help secure your VoIP service, as well as what you can do on your network to secure your VoIP service.
== IP Allow List (restrict access by IP) ==
 
IP Lockdown - a VoIP number can be given an IP address to which is only allowed to register (iei.e. you can add the IP of your phone, and only that phone will be able to register) (this feature is only on the C and the Voiceless platforms, the legacy A server does not have this feature)
 
[[File:ControlPages-VoIP-IPLockdown.png|none|frame|IP Lockdown, comma separated etc.]]
 
On the Voiceless platform you can specify the IP as a subnet in CIDR format, ege.g. 192.0.2.0/29, and multiple IPs can be comma separated.
 
Valid examples:
128.66.0.1, 128.66.0.2, 128.66.0.9 (3 single IPv4 addresses)
128.66.0.0/27 (a IPv4 network range)
128.66.1.1, 128.66.2.0/24 (a single IPv4 and aan IPv4 network range)
2001:DB8::1 (a single IPv6 address)
2001:DB8::/48 (a IPv6 network block)
2001:DB8::/48, 128.66.0.0/27 (a IPv6 and aan IPv4 network block)
 
== Bill Warning Emails ==
 
*New IP/Agent - will log and email whenever a new IP or a new User Agent registers. (Default Setting)
*New Agent - will log and email only when a new User Agent registers. iei.e., the IP is able to change, but whenever we see a new User Agent then it will be logged and emailed.
*None - will not log or email, NOT RECOMMENDED!
*We email the email address as set on the individual phone number. If the email address is not set then an email won't be sent.
 
=Odd incoming calls that are not on the CDRs?=
If your phone receives odd calls that are not logged on the AAISP CDR pages, then it may be that calls are being sent direct to your phone from the Internet. This would be because your phone or phone system is not firewalling SIP, and so auto-diallers are trying to make spammy calls to you. The caller id may be anything, but we have seen calls from 100, 150, 1000, 2000 etc. Also check your SIP logs to look for the SIP INVITE packet and see what the source IP is. ege.g., a SNOM has a SIP Log from within the web interface.
 
Solution: Firewall SIP as explained above.
editor
698

edits