
22
4. Configuring the SIP Security Policies
4.1. SIP Attacks Detection Policies
The SIP Attack Detection page allows to configure the SIP Deep packet Inspection rules
categories. The administrator can enable/disable the inspection against a particular
category of rules, action to be taken on detecting attacks matching the rules in the
categories.
The possible actions that the SIP Firewall can execute are logging the alert, block the
packets containing the attack vector and blacklist the attacker IP for the given duration.
The blocking duration of how long the attacker up needs to be blocked is also configured
per category level.
Figure 16: SIP Attacks Detection
The table given below lists the SIP Deep packet Inspection rules categories supported in
SIP Firewall and configuration parameters in each category.
Summary of Contents for SIP Firewall
Page 1: ......
Page 2: ...Elastix SIP Firewall User Manual ...
Page 23: ...21 Figure 15 Logging ...
Page 33: ...31 Figure 25 Geo IP Filters ...