Skip to content

Security

Any SIP server exposed to the Internet is continuously probed by automated scanners looking for weak credentials and open relays. The Security settings give you one place to manage the network-level defenses that keep that traffic out: which sources are always trusted, which are blocked, which SIP clients are rejected outright, and how sudden floods of requests are throttled. Keeping these current is a core part of protecting your platform from unauthorized access, toll fraud, and denial-of-service attacks.

Trusted IPs

Define IP addresses and ranges that are always allowed to reach the system, bypassing intrusion detection and automatic banning. Use this for your own offices, monitoring systems, and known carriers so legitimate traffic is never accidentally blocked. See Trusted IPs for details.

Banned IPs Management

View the IP addresses that intrusion detection has currently banned, release any that were blocked in error, and configure permanent bans for sources you never want to hear from. See Banned IPs Management for details.

Banned User Agents

Block specific SIP user agents (the User-Agent string a device or scanner presents) from registering or sending requests. Many attack tools identify themselves with recognizable user agents, so blocking them stops a whole class of automated probes cheaply. See Banned User Agents for details.

Traffic Control

Configure rate limiting and traffic-shaping rules that detect and dampen sudden spikes in SIP requests, protecting the platform against SIP flooding and denial-of-service attacks. See Traffic Control for details.

Best practices

  • Add your trusted sources first. Before tightening banning and rate limits, list your offices, SBCs, monitoring, and carriers under Trusted IPs so a strict policy never locks out legitimate traffic.
  • Review banned IPs periodically to confirm no real users or carriers were caught, and to spot ongoing attack patterns.
  • Use permanent bans for persistent abusers rather than relying on automatic, time-limited bans alone.
  • Combine layers. IP trust/bans, user-agent blocking, and traffic control complement each other - use them together rather than depending on any single control.
  • Pair network security with strong credentials. These controls reduce exposure, but strong SIP passwords and TLS (SIP Encryption (TLS)) remain essential.

Keep Trusted IPs up to date and review Banned IPs periodically to ensure legitimate traffic is not being blocked.