Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How can I trace malicious SIP traffic

Status
Not open for further replies.

danisrael

IS-IT--Management
Jan 29, 2013
80
US
With COVID forcing our workers remote. We have opened up SIP. However, we are getting some malicious attempts to login as a sip user for IP office. While they are not succeding, we would like to blacklist the repeated ones. The IPO is provides lockout for 300 seconds, and that will show the IP in system status. But is there a way to setup the filter on Monitor to see and obtain the IPs?
 
Best way to avoid it is to use TLS when allowing external SIP devices, it's also good to use encryption so you don't send authentication details in clear view over the internet.
It's also rare that SIP scanners try to connect over TLS.

In later R11 you can also blacklist all non-Avaya User Agents, or whitelist specific User Agents etc.

Blocking IPs are usually pointless since they constantly change which IP they originate from.


"Trying is the first step to failure..." - Homer
 
In addition
any blocking should idealy be done at the router not the IP office



Do things on the cheap & it will cost you dear
 
In monitor, under status there are options for list of blacklisted extensions and IP addresses. Since 10.1 I think.



Stuck in a never ending cycle of file copying.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top