Configuring Sip Message Policy Rules - AudioCodes E-SBC User Manual

Hide thumbs Also See for E-SBC:
Table of Contents

Advertisement

CHAPTER 21    SIP Message Manipulation
3.
Configure a Message Condition rule according to the parameters described in the table below.
4.
Click Apply.
An example of configured Message Condition rules is shown in the figure below:
Index 0: Incoming SIP dialog that is classified as belonging to a User-type IP Group.
Index 1: Incoming SIP dialog that contains a SIP Via header.
Index 2: Incoming SIP dialog with "101" as the user part in the SIP From header.
Table 21-2: Message Conditions Table Parameter Descriptions
Parameter
'Index'
[ConditionTable_
Index]
'Name'
name
[ConditionTable_
Name]
'Condition'
condition
[ConditionTable_
Condition]

Configuring SIP Message Policy Rules

The Message Policies table lets you configure up to 20 SIP Message Policy rules. SIP Message
Policy rules are used to block (blacklist) unwanted incoming SIP messages or permit (whitelist)
receipt of desired SIP messages. You can configure legal and illegal characteristics of SIP
messages. This feature is helpful against VoIP fuzzing (also known as robustness testing), which
sends different types of packets to its "victims" for finding bugs and vulnerabilities. For example,
the attacker might try sending a SIP message containing either an oversized parameter or too many
occurrences of a parameter.
You can also enable the Message Policy to protect the device against incoming SIP messages
with malicious signature patterns, which identify specific scanning tools used by attackers to
search for SIP servers in a network. To configure Malicious Signatures, see
Signatures.
Each Message Policy rule can be configured with the following:
Maximum message length
Defines an index number for the new table row.
Note: Each row must be configured with a unique index.
Defines a descriptive name, which is used when associating the row in
other tables.
The valid value is a string of up to 59 characters.
Note: The parameter value cannot contain a forward slash (/).
Defines the condition of the SIP message.
The valid value is a string. You can use the built-in syntax editor to help
you configure the field. Click the Editor button located alongside the field
to open the Editor, and then simply follow the on-screen instructions.
Note: User and host parts must be enclosed in single quotes.
- 516 -
Mediant 1000 Gateway & E-SBC | User's Manual
Description
Configuring Malicious

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mediant 1000b

Table of Contents