Voice gateway protection: SIP, SRST

Unanswered Question
Oct 1st, 2008
User Badges:

Hello, we have a SIP gateway and need to find a way to prevent "untrusted" phones from sending SIP messages to gain unauthorized access to make calls over the PSTN.


It is not possible to implement an access-list to reject SIP messages from the subnets where phones may reside (thereby accepting signalling only from the CallManagers), as this gateway is also providing SRST services.


Is there any way that security can be enforced in this scenario?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
amritpatek Tue, 10/07/2008 - 13:31
User Badges:
  • Silver, 250 points or more

The Cisco Multiservice IP-to-IP Gateway available on Cisco IOS voice gateways provides a toolkit of session border controller functions. These include signal interworking between SIP and H.323, security with firewall and denial of service protection, topology hiding with address and port translations, billing and call detail record normalization, QoS and bandwidth management.

alex_degruiter Mon, 10/27/2008 - 20:32
User Badges:

I should have been more clear - the CUCM-IOS interface is SIP, however the PSTN connection is ISDN Q931.

Actions

This Discussion