Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

SIP Trunk Security 3

Status
Not open for further replies.

exsmogger

Vendor
Oct 23, 2002
5,243
US
Hi all,

Many of you saw the thread I started on SIP trunk ghost calls. I had intended to build a firewall from a Raspberry Pi and place it in front of my BCM50, but the project turned out to be more complex than I thought in trying to program iptables firewall software. Since my project involved adding a second Ethernet port to the Pi I had to create a network bridge which seriously changed the way packets flow through the firewall. It sort of worked, but not nearly good enough. I shelved that idea for the time being and came up with another solution that has shielded my BCM50 from the SIP scanners, but also allows my SIP trunks to work behind NAT without having to use port forwarding. Attached is a Word document I wrote that details the process I went through.

Brian Cox
Georgia Telephone

 
Nice, have a star.

________________________________________

Add me to LinkedIN

small-logo-sig.png

=----(((((((((()----=
Toronto, CAN
 
Thanks gents. This is a work in progress as the script kiddies are always looking for new methods in their quest for "free" phone calls. I believe the SIP providers need to take more responsibility for security than they do currently. I absolutely cringe at all the articles on SIP that advise people to forward port 5060 to their phone system.

Brian Cox
Georgia Telephone
 
Super! a star too.
 
I appreciate that. All is still quiet on my BCM50 since I figured out how to keep my system behind NAT and at the same time allow real calls to come through. I haven't had even one SIP scanner hit my system in almost 2 weeks. The firewall is doing its job.

Brian Cox
Georgia Telephone
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top