Is there anyway to automatically block: Unidentified Incoming Call.

greychain

Gold Partner
Advanced Certified
Joined
Jul 13, 2018
Messages
779
Reaction score
122
I'd like to know if I can automatically add these to the IP blacklist on 3CX, their just annoying. Also report them to 3CX to add to the global blacklist

Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:[email protected]:5060 SIP/2.0. Via: SIP/2.0/UDP 153.75.89.150:5493;branch=z9hG4bK2f6f7ce6-602e-5965-vua6a157e274vinz;rport=5493. Max-Forwards: 70. Contact: <sip:[email protected]:5493>. To: <sip:[email protected]:5060>. From: <sip:[email protected]:5493>;tag=hq4kvey1kcbo8f09. Call-ID: dZ1UWKV8DjKkPW5roMQMxXuTLHHqHa22yBbG4QIh. CSeq: 1 INVITE. Content-Type: application/sdp. User-Agent: Cisco-SIPGateway/IOS-12.x. Content-Length: 741. v=0. o=- 1551542923 1551542924 IN IP4 153.75.89.150. s=cisco-sipgateway/ios-12x. c=IN IP4 153.75.89.150. t=0 0. m=audio 20002 RTP/AVP 9 104 98 3 8 0 101 97 100 108 15 4 105 106 107 103 103 103 18. a=rtpmap:9 G722/8000. a=fmtp:9 bitrate=64000. a=rtpmap:104 G726-16/8000. a=rtpmap:98 iLBC/8000. a=fmtp:98 mode=20. a=rtpmap:3 GSM/8000. a=rtpmap:8 PCMA/8000. a=rtpmap:0 PCMU/8000. a=rtpmap:101 telephone-event/8000. a=rtpmap:97 SPEEX/8000. a=rtpmap:100 SPEEX/16000. a=rtpmap:108 SPEEX/32000. a=rtpmap:15 G728/8000. a=rtpmap:4 G723/8000. a=rtpmap:105 G726-24/8000. a=rtpmap:106 G726-32/8000. a=rtpmap:107 G726-40/8000. a=rtpmap:103 L16/8000. a=rtpmap:103 L16/44000. a=rtpmap:103 L16/44000. a=rtpmap:18 G729/8000. a=fmtp:18 annexb=no. a=sendrecv
 
I'd like to know if I can automatically add these to the IP blacklist on 3CX, their just annoying.
I have to admit, I don't recognize these numbers and I have little desire to look up the IP addresses right now. I assume these are unwanted direct SIP calls appearing in the 3CX logs that are being reported.

If that is the case, please read this at first:
https://www.3cx.com/community/threads/allow-only-those-ips-listed-at-allow.132637/post-632169

You can also handle it the way we do. Since we do not use (and do not intend to use) direct SIP calls, we - if we allow incoming SIP requests at all - restrict access at the upstream firewall exclusively to the IP networks of the specific SIP trunk provider being used. These networks are documented or at least should be.

Another possible solution is adjusting the 3CX parameter SEC_IGNORE_USER_AGENT.
 
You could also alter the limits in Admin > Advanced > Anti-Hacking to limit the amount of noise one IP generates.
 

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK