No subject


Sun Jul 19 19:54:31 CDT 2009


interest in receiving calls from, so I just block a lot (too many?) of 
class A addresses. Unfortunately, my web server and email server are on 
the same host, so I need to refine this approach a bit :)

A better approach would be to specifically allow the IP addresses of the 
callers you expect, and drop everybody else.

If you have multiple IP addresses (for example, a public and a private) on 
your Asterisk box, binding SIP, IAX, and the manager interface to the 
local address will also reduce your attack profile.

-- 
Thanks in advance,
-------------------------------------------------------------------------
Steve Edwards       sedwards at sedwards.com      Voice: +1-760-468-3867 PST
Newline                                              Fax: +1-760-731-3000



More information about the asterisk-biz mailing list