390
SMG Digital Gateway
APPENDIX F. GUIDELINES FOR SMG OPERATION IN PUBLIC NETWORK
During SMG operation in a public network, you should take all security measures in order to avoid the
device password brute forcing, DoS (DDoS) attacks and other intrusive actions that may lead to unstable
operation, subscriber data theft, attempts to perform calls at the expense of other subscribers and consequently
to damages to the service provider as well as subscribers.
Avoid using SMG in a public network without additional protective measures like session border controller
(SBC), firewall, etc.
Guidelines for SMG operation in public network:
Operation in a public network with default SIP signalling port 5060 is not recommended. To
change this parameter, modify the 'Port for SIP signalling reception' parameter value in 'SIP
interfaces' settings for general SIP configuration and SIP interface settings
1
. This setting will not
ensure the complete protection as the signalling port may be discovered during port scanning.
If IP addresses of all devices communicating with SMG are known, use the embedded firewall
(static firewall) to configure the allowing rules for them and deny the access from all the other
addresses. Allowing rules should be placed first in the rule list.
Also, you should configure dynamic firewall.
Dynamic firewall stores unsuccessful SIP protocol access attempts in a log file (/tmp/log/pbx_sip_bun.log)
and if the amount of such attempts exceeds the defined value, the IP address that has originated them will be
banned for the specified time. This utility also allows to create lists of trusted and untrusted addresses. For
detailed description, see Section 3.1.13.2 Dynamic firewall.
1
This function is available in version RC14 and later
Содержание SMG-1016M
Страница 1: ...SMG 1016M SMG 2016 Operation manual firmware version 3 10 1 Digital gateway ...
Страница 17: ...SMG Digital Gateway 17 Fig 5 V5 2 AN outstation based on SMG 1016M Fig 6 V5 2 AN outstation based on SMG 2016 ...
Страница 223: ...SMG Digital Gateway 223 As the result the call record categories table is displayed as follows ...