Banned User Agents
Banned User Agents blocks SIP clients based on the User-Agent header they present. Automated attack tools and SIP scanners identify themselves with recognizable User-Agent strings (for example the well-known scanning toolkits). Rejecting those strings outright drops a large share of malicious traffic before it can attempt a single registration or call, complementing the IP-based defenses in Traffic Control.
Because this filter matches on a request header rather than an address, it stops known bad tooling regardless of which IP it comes from - useful against attackers who rotate through many source addresses.
Banned User Agents
Banned User Agents. The list of blocked User-Agent values. It ships pre-populated with agents commonly used for SIP brute-force and system scanning. Add your own entries or remove ones that conflict with legitimate devices. Any SIP request whose User-Agent matches an entry is rejected.
Best practices
- Keep the shipped defaults. They cover the most common attack toolkits and rarely collide with real phones.
- Know your fleet’s User-Agents before adding entries. Legitimate phones and softphones each report a distinctive
User-Agent; blocking a substring that also appears in one of your devices’ strings will lock those devices out. When in doubt, check what your endpoints send before banning a value. - Combine, do not rely solely on this. Determined attackers can spoof any
User-Agent. Use this alongside Traffic Control, Trusted IPs, and strong SIP passwords.
Related documentation
- Traffic Control - rate-limit and auto-ban abusive source IPs.
- Trusted IPs - allow-list known-good sources.
- Banned IPs - permanently ban or unban addresses.