User's Manual
28. SBC Configuration
Version 6.8
481
Mediant 500 E-SBC
Note:
•
For security, it is recommended to classify SIP dialogs based on Proxy Set only if
the IP address of the Server-type IP Group is unknown. In other words, if the
Proxy Set associated with the IP Group is configured with an FQDN. In such
cases, the device classifies incoming SIP dialogs to the IP Group based on the
DNS-resolved IP address. If the IP address is known, it is recommended to use a
Classification rule instead (and disable the Classify by Proxy Set feature), where
the rule is configured with not only the IP address, but also with SIP message
characteristics to increase the strictness of the classification process. The reason
for preferring classification based on Proxy Set when the IP address is unknown is
that IP address forgery (commonly known as IP spoofing) is more difficult than
malicious SIP message tampering and therefore, using a Classification rule
without an IP address offers a weaker form of security. When classification is
based on Proxy Set, the Classification table for the specific IP Group is ignored.
•
If multiple IP Groups are associated with the same Proxy Set, use Classification
rules to classify the incoming dialogs to the IP Groups (do not use the Classify by
Proxy Set feature).
3.
Classification Stage 3 - Classification Table:
If classification based on Proxy Set
fails (or disabled), the device uses the Classification table to classify the SIP dialog to
an IP Group. If it locates a Classification rule whose characteristics (such as source IP
address) match the incoming SIP dialog, the SIP dialog is assigned to the associated
IP Group. In addition, if the Classification rule is defined as a whitelist, the SIP dialog
is allowed and proceeds with the manipulation, routing and other SBC processes. If
the Classification rule is defined as a blacklist, the SIP dialog is denied.
If the classification process fails, the device rejects or allows the call, depending on the
setting of the 'Unclassified Calls' parameter (on the General Settings page -
Configuration
tab >
VoIP
menu >
SBC
>
General Settings
). If this parameter is set to
Allow
, the
incoming SIP dialog is assigned to an IP Group as follows:
1.
The device checks on which SIP listening port (e.g., 5061) the incoming SIP dialog
request arrived and the SIP Interface which is configured with this port (in the SIP
Interface table).
2.
The device checks the SRD that is associated with this SIP Interface (in the SIP
Interface table) and then classifies the SIP dialog with the first IP Group that is
associated with this SRD. For example, if IP Groups 3 and 4 use the same SRD, the
device classifies the call to IP Group 3.
Note:
If classification for a SIP request fails and the device is configured to reject
unclassified calls, the device can send a specific SIP response code per SIP
interface. This is configured by the 'Classification Failure Response Type' parameter
in the SIP Interface table (see ''Configuring SIP Interfaces'' on page
Summary of Contents for Mediant 500 E-SBC
Page 2: ......
Page 16: ...User s Manual 16 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 22: ...User s Manual 22 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 23: ...Part I Getting Started with Initial Connectivity...
Page 24: ......
Page 26: ...User s Manual 26 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 28: ...User s Manual 28 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 33: ...Part II Management Tools...
Page 34: ......
Page 36: ...User s Manual 36 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 64: ...User s Manual 64 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 82: ...User s Manual 82 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 89: ...Part III General System Settings...
Page 90: ......
Page 106: ...User s Manual 106 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 107: ...Part IV General VoIP Configuration...
Page 108: ......
Page 238: ...User s Manual 238 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 250: ...User s Manual 250 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 280: ...User s Manual 280 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 329: ...Part V Gateway Application...
Page 330: ......
Page 332: ...User s Manual 332 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 352: ...User s Manual 352 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 412: ...User s Manual 412 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 441: ...Part VI Session Border Controller Application...
Page 442: ......
Page 489: ...User s Manual 28 SBC Configuration Version 6 8 489 Mediant 500 E SBC...
Page 510: ...User s Manual 510 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 511: ...Part VII Cloud Resilience Package...
Page 512: ......
Page 521: ...Part VIII High Availability System...
Page 522: ......
Page 536: ...User s Manual 536 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 537: ...Part IX Maintenance...
Page 538: ......
Page 544: ...User s Manual 544 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 546: ...User s Manual 546 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 548: ...User s Manual 548 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 582: ...User s Manual 582 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 600: ...User s Manual 600 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 602: ...User s Manual 602 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 603: ...Part X Status Performance Monitoring and Reporting...
Page 604: ......
Page 654: ...User s Manual 654 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 655: ...Part XI Diagnostics...
Page 656: ......
Page 672: ...User s Manual 672 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...
Page 687: ...Part XII Appendix...
Page 688: ......
Page 914: ...User s Manual 914 Document LTRT 10437 Mediant 500 E SBC This page is intentionally left blank...