SIP spam attack and MCU and vcs - e call

as far as I know sip call spam attacks is done against the videoconference, connected with a public ip address, I disabled the sip but im not sure if my mcu and vcs - e with sound are vulnerable to them? they pose no threat to security for them? and if so, how? and what can we do about it?

It is a well known problem and it affects H.323 and SIP, take a look at the below threads:

https://supportforums.Cisco.com/discussion/12340591/nuisance-h323-calls-SX20

https://supportforums.Cisco.com/discussion/12336591/sourceh323idcisco-incomingcalls

https://supportforums.Cisco.com/discussion/12508641/Cisco-source-spam-calls-stepped-complexity

https://supportforums.Cisco.com/discussion/12613681/attack-vcse

There are many more discussions on this issue, the above, this is just a small selection. :)

You do not need to disable SIP on the VCS-E, all you need to do is turn SIP UDP unless you need it for voice services.

You can protect yourself by using a CPL on the VCS-E who will avoid calls to go through your MCU, or anything else you have sitting behind the VCS-E. This is assuming that you are using a combo of VCS-C/VCS-E, with the VCS - C behind a firewall and the VCS-E outside the firewall, for example in the demilitarized zone.

Having just trouble ask points of termination or MCU sitting in nature with public IP addresses.

These scans, moreover, mainly looking for systems that will allow them to make free international calls.

/Jens

Please evaluate the answers and makr as 'answered' questions as appropriate.

Tags: Cisco Support

Similar Questions

  • A box pops up saying that Firefox on my iPad is in danger of virus attack and need to call an 800 number. It's from you, and I should call? If not...

    A box popped up on Firefox when I tried to go on the Internet, and I have to call an 800 number to get this good. What is Firefox and I can trust him? If this is not the case, how can I get rid of this box. The only answer to that is 'normal', but even when I click on it, the box will not disappear.

    You should never reply to a message to call a specific number or install the cleaning/repair software.
    That will probably get you in trouble (not sure where you are) and Mozilla will never use this method.

  • video conferencing through vcs-e and vcs - c

    can I make calls using video conferencing devices using vcs - c and vcs - e only? or is cucm involved in the process? also if I set my camera to call using only H.323 and SIP disabled, can I call sip addresses? also if im calling via vcs - c and vcs-e do I need to implement natting to the local address of videoconferencing unit? Lastly can someone please link any document on how to set my vcs - c and vcs-e and my videoconferencing unit to send and receive sip and h323 calls.

    "can I make calls by means of video conference devices using vcs - c and vcs - e only? or is cucm involved in the process? »

    If there are termination points recorded on the CUCM and want to call the end points on the VCS, CUCM is involved in the appeal process as the call goes through the trunk SIP between CUCM and VCS. Even also on the endpoints registered on VCS if they call endpoints on CUCM.

    If end points locally stored on the VCS and making calls to another, CUCM is not involved.

    "also if I set my camera to call using only H.323 and SIP disabled, can I call sip addresses?

    Yes, so that interoperability is enabled on your VCS.

    "also if im calling via vcs - c and vcs-e do I need to implement natting to the local address of videoconferencing unit?"

    No need. The VCS - c and VCS - e will do their work for calls of crossing of firewall. Until the end point is stored on the VCS then an area between these VCS are enabled, you can join located outside the network of endpoints and they can also reach your internal termination points as well.

    The Cisco VCS Expressway and the VCS control - Basic Configuration will be the guide you're looking for.

    http://www.Cisco.com/c/dam/en/us/TD/docs/Telepresence/infrastructure/VCs/config_guide/x8-7/Cisco-VCs-basic-configuration-control-with-Expressway-deployment-guide-x8-7.PDF

    Kind regards

    Acevirgil

  • 2 MCU and VCS Expressway, routing problem

    Hi all

    We have a design with a group of control VCS (2 members), cluster VCS Expressway (2 members), and a couple of microcontrollers (registred H.323 on VCS control cluster with the same prefix: 90).

    Each highway has a public IP address and incoming calls from outside can only be routed to microcontrollers:

    [email protected]/ * / for MCU_1 and [email protected]/ * / for MCU_2 (we don't have external DNS resolution).

    I put a conversion into motorway of VCS to change [email protected]/ * / to [email protected] / * / and [email protected]/ * / to [email protected] / * /.

    The problem is when someone calls [email protected]/ * / sometimes (randomly) the call is routed to MCU_2 (instead of MCU_1) and if the appellant see the auto attendant.

    The occcurs even then of the appeal [email protected]/ * / (MCU_2), sometimes the call is routed to MCU_1.

    Any idea what can cause this device or a way to make it work well?

    Thanks for help.

    José

    I think still that separate prefix would work, but here are a few ideas:

    Are incoming calls which do not possibly using SIP that is being interoperability H323 or incoming calls all certainly the H323?

    If you want to keep pure H323, you could perhaps just have a search rule/turn on your VCS-E who changed [email protected] to an E164 e.g. 90... and had a search on your VCS - C rule that says 90... stop at the local area.

    I also noticed that you direct calls to [number]@MCU-IP - have you tried to direct all calls to [number]@VCS-C IP instead?  If the VCS is the holder of a registration for a number, it should be able to deliver accordingly.

  • Control of VCS and VCS expressway design

    I have a problem with the design of control and track Express VCS. Now, here's two VCS control and a highway. As you know, put on the Internet Highway and a control on my seat. At the same time, I want to put the other control on the management of my company which is in another city. Can it work correctly? How dose it work?

    You must create two zones on VCS Expressway crossing server and a customer journey area by control VCS.

    In other words, you should have a link path by VCS - C connection VCS-E separately.

    Please be sure to set different H.323/SIP port on each VCS - C.

    For example:

    VCS - C1 (Headquarters): area of traversal client pointing to VCS-E 6001 as port H323 and SIP traversal port 7001.

    VCS - C2 (branch): area of traversal client pointing to VCS - E with 6002 as port H323 and SIP traversal port 7002.

    VCS-E: a traversal server zone list for VCS - C1 (6001 as port H323 and SIP traversal port 7001) and other traversal server list for VCS - C2 (6002 as port H323 and SIP traversal port 7002)

  • Where can I find documentation on how to get the VCS - C and VCS-E to Exchange presence information

    I turned presence on my VCS - C and VCS-E, but depending on whether I am VPNed or not, I don't see the State of the presence of my side of the firewall.

    I checked for x7.1 Administrator's guide, I looked in the guide of authentication devices, and I'm at a bit of a loss.

    Is what I'm trying to do as possible, and if so, what do I have to do to make this work?

    I have a pretty simple setup - that works very well, could give you some ideas;

    Two VCS - Independent C (soon to be clustered) and a VCS-E;

    all internal clients of the JabberVideo register with a VCS - C, and when external registers with the VCS-E (all of my users of Singapore recorded with the VCS-E).

    Authentication is directly with AD and is made on the a WHAT VCS - C regardless of the user is registered with the VCS - C or the VCS-E.

    PUA and presence disabled on VCS-E and activated on the VCS - C, which is used as SIP registrar.

    Authentication on VCS - e:

    Default subfield "do not check".

    Default zone "do not check".

    Traversal server box "do not check".

    Authentication on VCS - C:

    Default subfield "audit powers.

    MOVI area 'audit powers.

    Point final SIP registration box "treat as authenticated.

    Course customer area 'audit powers.

    Authentication works well, the users cannot sign up for the VCS-E with the wrong password or user name, and presence works well too - both inside and outside.

    /Jens

  • Tests EX60 UCM and VCS registration

    Hello

    I did a few test with Cisco EX60 a few days ago a the following infrastructure:

    -UCM 8.6.2

    -Cisco VCS control X7.2.2

    -Cisco EX60 series

    -Csco EX90 series

    -Cisco CPIC

    -Cisco IP Phone

    The goal was to try to save the EX60 in SIP mode with UCM and H.323 mode in VCSC and make some calls with EX60 register in both devices, because I have found no documents where it was stated that only I can save EX60, EX90 in VCS or Complutense University of MADRID, but not in both at the same time.

    I recorded the EX90 in VCS and EX60 in VCS (H.323) and UCM (SIP).

    All calls to H.323 devices EX60 send control VCS and all calls all works fine without any problems. If I try to call EX90 to EX60 in SIP mode, the call will be fails. When the EX90 with EX60 H.323 call is connected, the University Complutense of MADRID and using RTMT I saw that the EX60 was on appeal or in busy state.

    -Audio call of the registered IP phone or CPIC to the AAU to EX60: I saw the call in the call control in the EX60 and RTMT and Complutense University of MADRID, but I did not see the call to the control VCS Cisco. If I try to call to EX90 to EX60 using H.323 right now, I got an EX60 busy tone. Also, if I make an audio call to EX60 for an IP phone I can do another audio EX60 call to an IP phone or an EX90. EX90 try to video negotited but calls finally was audio only.

    -The presence does not work when the EX60 is under appeal with the other end H.323 in the Complutense University of MADRID, too the BLFs do not work and does not appear the call at the Complutense University of MADRID.

    -Si EX60 is videoconferencing with EX90, the EX60 can receive an audio call to UCM get connect and the presence and the BLFs working properly.

    I find no more problems at the moment.

    Kind regards.

    This isn't a Setup program that you want to use, or register them both to the VCSC or

    Let CUCM control your end point, then h323 must be disabled.

  • VCS - C and VCS-E switch to x8.7

    Hi, I plan on upgrading to VCS version x8.7 (of x8.2) to meet the needs of encryption for a RMC-cloud deployment and looking for some feedback from the community on a number of things:

    -I shouldn't need a key to unlock because the upgrade is the same version, correct?

    -J' need to upgrade the VCS - C and VCS - E with the same version of software, correct?

    N ' needs nothing to do away with the MCU? We are currently at version 4.5 software (1.45).

    Thanks for your help,

    Brad

    Release keys are only required if the major software version changes, minor changes for example, ranging from X8.2 to X8.7 does not require a key to unlocking.

    VCS - C and E must be on the same version, the only time where they should be on separate versions is when software updates.

    Nothing should be changed from the MCU.

  • Issue with LINK ISDN and VCS

    Dear Expert

    Link ISDN is capable of working with VCS?

    As I go through the link Cisco TelePresence ISDN administrator guide, he said that endpoint must be registered at VSC when you use the mode ISDN PRI E1 and ISDN BRI Euro type.

    Is that means whenever I want to make a call ISDN with ISDN LINK, I de-register endpoint of VSC on gateway H323 and SIP pox

    Currently my endpoints use VCS as gateway H323 and SIP pox

    Thank you

    Tung

    Hello Tung!

    I wasn't looking for it, but I would say that the Administrator's guide shows just examples, which could

    be configured, not exclusive requirements.

    See the section called "Complete example with an IP infrastructure" and VCS

    In short, endpoint is connected to ISDNlink device and the ISDN link records for VCS.

  • Can't find the email that I need to get back in the Spam report and not in the junk e-mail folder.

    I regularly get Spam Report emails in Mozilla Thunderbird, but I don't know how to retrieve those that I I want off that e-mail. I checked the spam folder, and they are not in. How do I find/recover these?

    I use a MacBook Pro, OSX 10.9.3 version

    Thank you!

    Thunderbird does not use the term Spam and I do not believe that it delivers any form of Spam report. It can receive one issued by your email provider. I sign in to your account to your web e-mail providers page and check their spam folder to see what is there.

  • Hi have a virus on my email software. He continues to send spam emails and cannot be deleted

    Hello

    have an I-phone 6 + there seems to be a virus on the messaging of the software. He continues to send spam emails and you can not delete your emails that they keep coming back

    help thank you

    Nope.  There is no virus running on iOS.

    Most likely your computer has been hacked / infected.

  • If I leave my desktop computer all the time, my computer open to attack and or infection?

    I am concerned about leaving my computer all the time. If I leave all the time open the computer to attack and or infection?

    Thanks for the information.

  • E-mail sent to the "Spam" folder and this is not spam

    I'm sure this has already been answered, but I searched here and internet and maybe I'm not right worded research but most of them answer questions such as "undesirable" (and this isn't the case I'm talking about) and others have answers as envoys of their e-mail that the individual doesn't send spam.

    My question is this new junk e-mail filter.  I've got things going in my spam folder that are not spam.  I clicked on "Add sender to sender list", "add the domain of the sender to the list of sender" and "Add sender to contacts" but email keeps going into the spam filter and if I try to move it to the Inbox folder or drag and drop it into the Inbox folder, the email will just immediately in spam. I don't mind having to look at what is in your spam folder, but it can get a little irritating at times.  Actually at first I would see these flash like e-mail being received but had no idea, even after the search in the "junk" folder, where they were going... it was not until a week or so later that I noticed that the folder spam.

    Anyway, how I have - or can I? -through the 'spam' email 'Inbox' and have it shipped here?  I think I tried everything that is done usually for example by adding the contact but... it does not work.

    Thank you

    Kerri

    Windows Mail has a junk e-mail folder. If you have a Spam folder, it is a product of a third-party spam program, and this is where you need to look for your answers.  Bruce Hagen ~ MS - MVP [Mail]

  • Windows Vista security alert sending indicating virus attack and does not allow me to get security alerts. How to bypass or disable?

    Windows Vista security alert sending indicating virus attack and does not allow me to get security alerts.  How to bypass or disable?  I have another anti-spyware (Kapersky) program that manages all aspects and indicates no virus found.

    I want to disable Vista, but it won't let me and the only solution it says is to download a update for a cost.  Help, please.

    The 'alert' is not from Vista. Your computer is infected by a rogue security program. It's called "thugs" because he pretended to be a good guy but is really bad. Don't pay them!

    Bleeping Computer has the removal of many variants of thieves here steps - http://www.bleepingcomputer.com/virus-removal/remove-antivirus-vista-2010
    You can also check for the stages of removal at these links:

    Bleeping computer removal how - to - http://www.bleepingcomputer.com/forums/forum55.html
    Malwarebytes malware removal guide - http://tinyurl.com/5xrpft

    Malwarebytes' Anti-malware (MBAM) or SuperAntiSpyware will often do the job. Both have free versions and you don't need to buy these programs.

    These can work for you, and all can be good. However, in many cases the computer will also infected with other horses of Trojan and protected by a rootkit. These machines are extremely difficult to clean. If your machine is one of these cases, either the interactive assistance to one of the specialty forums listed in the link below, OR take your machine to a professional on the local computer OR backup your data and do a clean install of Windows. It's your choice. I do not recommend using BigComputerStore/GeekSquad types of places.

    http://www.elephantboycomputers.com/page2.html#HJT-links MS - MVP - Elephant Boy computers - don't panic!

  • Call the flow of VCS-E and VCS - C

    Hi all

    I'm looking for some documents describing the call flow of VCS-E and VCS - C in H.323 as the jpg I have attached.

    (Especially when endpoint dials on internet to the intranet)

    Are there documents like tthat?

    Best regards

    Kotaro Hashimoto

    Call the stream while VCS - E uses the SANCTION for traversal Protocol (almost identical even use H.460.18 to signal flow).

    Please note that this call flow only not understand key messages each Exchange of messages between VCS & endpoint as well as VCS-E & VCS - C.

Maybe you are looking for