Hi
>Something you may want to consider is to put ACLs as far upstream as possible
>from your SBCs and only allow through what you need to the SBCs. For example,
>apply a filter only permitting UDP 5060 and your RTP port range to your SBCs
>and then blocking everything else. This is free and s
mpton, Rich A"
Cc: NANOG list
Subject: Re: [EXTERNAL] VoIP Provider DDoSes
CAUTION: The e-mail below is from an external source. Please exercise caution
before opening attachments, clicking links, or following guidance.
*nods* We have a Metaswitch SBC.
So as long as the pipe isn't full
dwest-ix.com
- Original Message -
From: "Rich A Compton"
To: "Mike Hammett" , "NANOG"
Sent: Tuesday, September 21, 2021 4:59:06 PM
Subject: Re: [EXTERNAL] VoIP Provider DDoSes
Most of the larger DDoS mitigation appliances can block malformed SIP tra
proxy based
firewall just for VoIP.
-Rich
From: NANOG on behalf of
Mike Hammett
Date: Tuesday, September 21, 2021 at 3:31 PM
To: NANOG list
Subject: [EXTERNAL] VoIP Provider DDoSes
CAUTION: The e-mail below is from an external source. Please exercise caution
before opening attachments, clicking
4 matches
Mail list logo