SIP support
Configuring SIP
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
433
•
Enabling SIP support from the CLI
From the FortiGate CLI, you can enable rate limiting for a more extensive range of SIP
requests, including ACK, INFO, NOTIFY, OPTIONS, PRACK, REFER, SUBSCRIBE, and
UPDATE. For more information, see the
.
From the CLI, you enable SIP support using the
config application list
command
to add SIP to an application list. The
config application list
command uses
application list numbers to identify applications. SIP is application number 12.
Use the following command to enable SIP support in an application list:
config application list
edit <list_name>
config entries
edit 12
end
end
Entering this command enables SIP support with all SIP settings set to defaults. See the
for information about all of the SIP settings and their defaults.
Setting SIP rate limiting from the CLI
Use the following command to enable SIP support in an application list and configure SIP
rate limiting:
config application list
edit <list_name>
config entries
edit 12
set register-rate 100
set invite-rate 30
end
end
More about rate limiting
FortiGate units support rate limiting for the following types of VoIP traffic:
•
Session Initiation Protocol (SIP)
•
Skinny Call Control Protocol (SCCP)
•
Session Initiation Protocol for Instant Messaging and Presence Leveraging Extensions
(SIMPLE).
You can use rate limiting of these VoIP protocols to protect the FortiGate unit and your
network from SIP and SCCP Denial of Service (DoS) attacks. Rate limiting protects
against SIP DoS attacks by limiting the number of SIP REGISTER and INVITE requests
that the FortiGate unit receives per second. Rate limiting protects against SCCP DoS
attacks by limiting the number of SCCP call setup messages that the FortiGate unit
receives per minute.
When VoIP rate limiting is enabled, if the FortiGate unit receives more messages per
second (or minute) than the configured rate, the extra messages are dropped.
If you are experiencing denial of service attacks from traffic using these VoIP protocols,
you can enable VoIP rate limiting and limit the rates for your network. Limit the rates
depending on the amount of SIP and SCCP traffic that you expect the FortiGate unit to be
handling. You can adjust the settings if some calls are lost or if the amount of SIP or
SCCP traffic is affecting FortiGate unit performance.
Содержание Gate 60D
Страница 678: ...Reports Log Report FortiGate Version 4 0 Administration Guide 678 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 704: ...Index FortiGate Version 4 0 Administration Guide 704 01 400 89802 20090424 http docs fortinet com Feedback...
Страница 705: ...www fortinet com...
Страница 706: ...www fortinet com...