monitor inbound SIP solutions?

Status
Not open for further replies.

rattler555

Silver Partner
Joined
Jan 12, 2021
Messages
48
Reaction score
10
Hello All,

I'm looking to setup some sort of way to test inbound calling over a SIP trunk from an upstream provider. We had issue with DDoS and would like to get alerted when inbound calling drops. Something that can place a test call and validate the endpoint receives the correct SIP messages should suffice. Does anyone know of any solutions or tools that have this capability?

Thanks!
JT
 
I'm sure you probably already know this but, just in case, if you are using Register based SIP Trunks 3CX has a built in email notification for when the Trunk unregisters.

It's under "Settings >> Email >> Notifications": "When the status of a trunk / SBC changes (SBCs are considered DOWN after 5 minutes of downtime)"

Also, to clarify, since you mention Inbound calling only, do you mean that you had issues that, caused the SIP Trunk to stay registered but not respond to incoming SIP INVITEs?
 
I'm sure you probably already know this but, just in case, if you are using Register based SIP Trunks 3CX has a built in email notification for when the Trunk unregisters.

It's under "Settings >> Email >> Notifications": "When the status of a trunk / SBC changes (SBCs are considered DOWN after 5 minutes of downtime)"

Also, to clarify, since you mention Inbound calling only, do you mean that you had issues that, caused the SIP Trunk to stay registered but not respond to incoming SIP INVITEs?
Yes, I do have this setup, in the last incident, only inbound calls were failing and registration stayed up. Damn Telnyx DDoS continuing. Getting better, but TLS was not working over Cloudflare, so I had to disable temporarily.

Thanks for the note.
 
If it's the SIP Provider who's under DDoS attack, that would mean that the receiving end (this case 3CX) would be none the wiser as it probably never even receives the call so you're looking for a 3rd node to actually initiate calls to your DID every now and then and report back if it failed?

Simplest way I can think of involving 3CX is to:

1. Use a second SIP Trunk exclusively for this purpose(the outgoing calls).
2. Enable "Trunk/Provider responds to Request with an Error code" under "Settings >> Email >> Notifications"
3. Use the 3CX CFD Dialer to "automate" outbound calls to your main DID.

I'm not 100% sure this is possible and that it would work for you though. I'd recommend first looking into point 3 to see if this is indeed possible to implement using the 3CX CFD the way you want. You might want to consider posting in our CFD section for help or more information on this.

Also, this will depend on the SIP Provider responding with a SIP Error. If the SIP Provider does not respond at all, as I would expect during a DDoS attack, the 3CX PBX generates an internal SIP Error (408 Request Timeout) and this should trigger the email notification. That said, since I cannot know for sure how the SIP Provider will behavior during such an event, I can't really say that this is the most reliable solution.

Hope this helps.
 
I've pondered this a time or two. You could spin up a $3 Lightsail server and install the free version of 3CX. Then create a service that calls certain phone numbers. If you wanted to take it a step further, you could call into a specific IVR and record the message played by the IVR. That would enable you to determine if audio is traversing, but that would require the Pro edition of 3CX ( suppose you could also use the Wireshark libraries to "listen" to the audio). Using the Call Control API, you could invoke the "MakeCall" on a scheduled basis and then using the size of the recording file you could determine whether audio was received (rather than doing the whole google voice-to-text thing). It's a service I have pondered building for 3CX partners/customers.
 
Status
Not open for further replies.

Forum statistics

Threads
111,994
Messages
590,183
Members
164,934
Latest member
bunthoeun.may