Protection of the SPA112/SPA122 of the outside traffic

Some of our resellers (ISPS in most cases) are huge problems with their client of SPA112/SPA122 lock up due to malicious traffic to SIP from the outside. To alleviate these problems, the best solution for us would be the ability to put the whole SPA112/122 VoIP service in one VLAN separated, i.e. the unit all of its 'clean' traffic marked with a personalized label of VLAN and provided regular service (bridge/nat) for not marked WAN traffic. I think some license of Cisco IP phone models.

Other options, we thought:

1 change port 5060 to something random source SIP

2 activate TLS on units

3. put an ACL in the unit allow SIP of our subnets traffic (not possible with the SPA112/122 to the best of my knowledge?)

.. .or other good way, minimum of effort and the pain is of course preferable. Allowing TLS would solve the issue? Customers with these problems are those who have connected their SPA directly to the internet, most often used as a router/bridge, the need of the solution to that account, placing the connection of any customer in one vlan voice is not an option.

Any advice on that? I guess that we are not alone in these matters...

Based on my best knowledge, the SPA phones has not been designed to be exposed to the public without restriction. They have no back implemented countermeasures and they seems to not be designed to be placed in the network accessible without restriction of global. Read Dangerous default, bill fraud can happen - it's so dangerous to have accessible unit unreliable peer.

You should put not only the ATA in separate VLANS. ATA special is allowed to speak to the PBX only (and vice versa). Direct communication between two ATA does not. Remember that anyone can disconnect ATA, connect the computer instead of him and attack no matter what ATA in the VLAN so.

Of course, it is not the solution for the distance units.

According to the options you mentioned...

[1] will help a lot if the unit is accessible worldwide, but even with it, this unit is in danger of back and/or unauthorized access

[2] ATA CPU not so powerful and TLS configuration is causing significant delays with call originating and answering. We have unacceptable to our users, but try it for yourself.

[3] ATA has no ACLs. The unit is designed to be placed in the secure network

I guess we're not the only ones with these issues...

I suspect that our approach will not help you much...

We arrange closed VPN between the user's network and dedicated to the<->Unit switch switch communication. Non - VPN packets are not allowed to join in everything and only switch unit and the switch packets are allowed to pass through the tunnel. We monitor the connection, we are responsible for the configuration and security unit of the ATA. User is not authorized to access its configuration at all.

But our users are sensitive to security and reliability.

I imagine a device connected to a network with security and uncertain reliability. But in this case, we cannot take any responsibility for the parameters out of our control. It is the responsibility of the customer to configure its network to be sure or take the risks associated with the device connected to the unsecured network...

Tags: Cisco Support

Similar Questions

  • How to hide my wireless connection personal House of the user of the computer on the outside

    I see from time to time by my window a vehicle that is parked outside using their computer. Someone told me that they can connect to the internet using my wireless signal. How can I hide the outside user I have a wireless connection?

    Hello Maria,.

    There are a few things you can do to make sure that you are safe.

    #1. Make sure that your wireless modem is protected using a personal code to access WEP or WPA2. This is done by going to the configuration of your modem and the establishment under the wireless tab / link / article. Of the modem user manual must be able to guide them in this process.

    #2. The other way is to disable the broadcasting network option in the modem. The only problem with this option, it is only people who are currently using the network can get on again.

    I recommend establishing a password on your wireless network and in this way people can see your broadcast network, but they will not be able to get on it, unless they have the password.

    Hope this helps,

    JB

  • Message to the outside, mail

    So I was on vacation for a week, come back today and learned that my message on the outside has absolutely nothing. I've got people who think that I just ignored the days now. I'm not happy.

    This IMAP account is on two computers, my job and my home. I've implemented the rule to the work and tested very well (not enforce), shut down the computer.

    At home, I don't think even to test the account again once and shut down the computer before leaving.

    I have to set up the answer further on EACH computer on which the IMAP account connected to it? or only for the last device that will receive mail? (Sense judgment of the work computer, go home, install the rule here, then stop that comp)

    Finally and this better not be true, but OSX Mail needs to be running for the rule to be active?

    If you configure the rule in your mail client, the client must be run to have the rule to work. Instead of putting in place such a rule is on the mail server. This by accessing the page from the server web mail.

  • Why Apple can't do two systems? First of all, we are protected, and the other is free just like android, but in the style of the iOS and Apple needs a request so we can manage and see new products from an application and do not go on this site!

    Why Apple can't do two systems? First of all, we are protected, and the other is free just like android, but in the style of the iOS and Apple needs a request so we can manage and see new products from an application and do not go on this site!

    and I don't know that if Apple make a system more freely, there no need for any device on Earth but iPhone.

    http://www.Apple.com/feedback/

  • 4 is not compatible with the protection of the identity of simple past on my HP using the player with the tips of the fingers. How can I make it work? IE9 works very well. Should I stop using FireFox?

    I have a HP DV7-4165 which has Windows 7 64 bit and simple features of the HP pass identity protection using the drive with the tips of the fingers. My Firefox support says "If you have the Firefox browser on your computer when your HP SimplePass Identity Protection software is installed, a Firefox extension will also be installed which enables support for the use of the fingerprints with the browser Firefox." Once I updated to Firefox 4 it no longer works.

    You can get Firefox 3.6.16 here:

    http://www.Mozilla.com/en-us/Firefox/all-older.html

  • Question of Safari and Chrome. indicates on the navigation screen. "An element of the Protection of the family filter does not work as expected. Restart your computer. If the problem persists, contact support.  Error: failed to hose CPI. »

    Question of Safari and Chrome. indicates on the navigation screen. "An element of the Protection of the family filter does not work as expected. Restart your computer. If the problem persists, contact support.  Error: failed to hose CPI. »

    Quit Safari, Chrome to quit smoking. If necessary Forcequit.

    Start Safari while holding the SHIFT key, select the menu Safari ClearHistory, then after this check that the homepage is the one you want.

    Do the same for Chrome.

    Close all browsers, restart the mac.

  • file index.xml missing existing password protected worksheet the worksheet

    file index.xml missing existing password protected worksheet the worksheet

    What spreadsheet, Excel,...? What model computer/year? What if any error message? Did you create the spreadsheet? Have you checked with the developer of the worksheet for help, Microsoft for example?

    Writing an effective question of communities of Apple Support

  • "Protection of the integrity of the system.

    I know that Apple has replaced the old system with a new permissions, because I had to disable the other to use my vertical mouse move.

    What are the effects downstream of a deactivation of "Protection of the integrity of the system"?

    What are the alternatives?

    Deactivation of "Protection of the integrity of the system" would explain the bugs some of us have some with dvd players?

    It would open up your machine to potential piracy as well as the loss of control over the permissions to change by ill-conceived installers. If security is a concern let alone SIP.

  • New ThinkPad T460p just arrived - the product name and serial number missing from the outside of the machine

    This page shows where the product name and serial number should supposed to be on my ThinkPad: https://support.lenovo.com/us/en/find-product-name?cid=EDM_2016_NA_US_PP_SUPPORT_V2&RRID=1014681098&...

    However, any of these are displayed on the outside of my machine anywhere.

    I happen to know the product name and serial number. I was able to find other ways - that is not the issue. As far as I know, these physical labels should have with the machine.

    Was it simply a mistake during Assembly, or Lenovo just stopped putting on these labels? If the first case, is there a way to ask Lenovo send me these labels? If the latter, Lenovo might consider updating the page linked above.

    Any inisight would be duly appreciated.

    Nicholas

    My T460p shows the T460p at the bottom right of the screen and the serial number and the code of the product under the battery. But the T460 is very dark on the corner of the screen, and Seraglio/product numbers appear on the very dark black label under the battery.

  • Need help to remove the protection of the family off account of girls

    I deleted my daughter from my laptop Microsoft account. I had the protection of the family there. How can I get the protection of the family out of his account because she has another account set up and know it required a code to get on his google account?  So I would like to remove the protection of the family so that it doesn't keep needing a code. If anyone can help me please and thank you.
     
    * This thread has been changed so that they the title is a little clearer. It will be also moved to a more appropriate forum hoping to teach you to someone who can answer your question correctly.  Thank you!

    Hello

    What operating system is installed on the computer?

    In the meantime, you can visit the link provided below to remove a parental control account.

    How can I remove parental control?

    Hope the information helps you resolve the issue.

  • computer is not allow to download a program on protected site, the "ongoing security scan" saying guard?

    computer is not allow to download a program on protected site, the "ongoing security scan" saying guard?

    Try temporarily disabling your Antivirus utility and try the download again.

    If you are running Microsoft Security Essentials, try disabling the real-time analysis and try the download again.

    Open Microsoft Security Essentials

    Go to settings, select "real-time protection".

    Uncheck the box and click on save changes.

  • I foolishly used my camcorder to the outside and the clips are too bright. How can I change the contrast on each of them in Movie Maker?

    I foolishly used my camcorder to the outside and the clips are too bright.  How can I change the contrast on each of them in Movie Maker?

    Use the effects... Decrease brightness / contrast down.

    Here are the steps to change all the clips on the timeline in a batch.

    Drag all the clips on the timeline... switch to... See the table of Storyboard.

    Reach... Edition / select all, or select an element and type... CTRL + A...

    Make a right click the effect you want to add and choose... Add to storyboard table.

    You can add up to 6 cases of an effect, but you need to left click
    a clip and "select all"... or type... Time of .ach Ctrl + A...

    It may take a little practice to master this, but it's easy once you see
    what he can do.

  • How can I disable protection of the customer

    How can I disable protection of the customer

    Hi pitellu,

    ·        What antivirus do?

    ·        Is it avant-garde or Microsoft Security Essentials?

    You could disable by using the parameter unless there is that a policy applies by administrator preventing turn he took.

    You can turn on or turn on the firewall in Windows XP, please see the link below:

    http://support.Microsoft.com/kb/283673

    Thank you and best regards,

    Imran M - Microsoft Support

  • How to create a restore point in the protection of the system in safe mode?

    As topic the question, how to create a restore point in the protection of the system in safe mode?

    Hello

    read a tutorial on the below link for everything you need to know about the system restore

    http://www.bleepingcomputer.com/tutorials/tutorial143.html

    and read this too

    System Restore: frequently asked questions

    http://Windows.Microsoft.com/en-us/Windows-Vista/system-restore-frequently-asked-questions

  • Flash drive, write protected after the use of Ready Boost

    I have a 8 GB USB flash drive, and I've been using ~ 4 GB for Ready Boost for quite a while now. When I tried to write something on the drive recently, I get a message saying that it is write protected. I tried to change the size of the cache, but has nothing - no error and no change. Tried turning off RB for the drive and nothing. There is no protection switch on the drive, so nothing to break. Tried to restart, refomratting the drive - no joy.

    Only, I could get a new drive because they are so cheap, but this one has a MicroSD in it like a separate disk drive, so I would keep

    Hello

    You can remove your usb flash drive write protection using the method below:
    a. open the start menu, in the search bar type regedit, and then press ENTER. This wil open the registry editor.
    b. navigate to the following location:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorageDevicePolicies
    Note:
    If StorageDevicePolicies registry key does not exist, you must create it manually.
    c. highlight StorageDevicePolicies, and then create a new DWORD called WriteProtect (32-bit).
    d. double-click the registration key in the right window, and then set it to a value of 0 in the value data box
    e. press OK
    Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems can occur if you modify the registry incorrectly. Therefore, make sure that you proceed with caution. For added protection, back up the registry before you edit it. Then you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click on the number below to view the article in the Microsoft Knowledge Base: 322756 (http://support.microsoft.com/kb/322756/ ) how to back up and restore the registry in Windows

Maybe you are looking for

  • How to customize the button for quick access to the search engine?

    There was no feature of grouping tabs in FF 3.6 and Ctrl + E keyboard shortcut has been to focus the cursor in the text field of the search engine (Web search pane).In FF 4 b 8 I can't find what is now this access key? How to change cursor to search

  • Why is free is not free?

    Whenever I have download an app that says it's free I ask me to verify my billing information and then I am charged. I thought free was free? Why is this happening? I want to download the new El Capitan, it is said that it is a free download, but onc

  • An update that messes with the keyboard

    HP Support Assistant was an update on 11/30/2015, almost all of my keys have been affected by the latter. My keys on the keyboard will work exactly correctly, ALL my keys. for an example, I could stand w to move in a game and he would have a work sto

  • Problem of Windows character map

    How can I reinstall Windows XP (SP3) charmap.exe? My system is missing 'C:\windows\system32\getuname.dll '.

  • I try to install Theme Hospital, but I need help :-(incompatibility with 64-bit

    I try to install Theme Hospital, but it says it cannot start or run due to incompatibility with 64-bit windows versions... y at - there a way around this? I REALLY want to play.