Skip to content

Traffic Control

Traffic Control protects your SIP service from floods of unwanted requests - port scans, registration brute-force attempts, and denial-of-service bursts. It measures how many SIP requests arrive from each source IP over a short window and automatically, temporarily blocks any address that exceeds the limit you set. This shields the platform from being overwhelmed and slows down attackers probing for weak accounts, while normal call and registration traffic passes through untouched.

Traffic Control works together with Trusted IPs: any address on the trusted list is never rate-limited or auto-banned. Add your carriers and office networks there so legitimate bursts are never mistaken for an attack.

Traffic Spike Control

Spike control counts requests per source IP within each Sampling Time Unit. If a single IP sends more than Max Requests in that window, all further requests from it are dropped and the IP is added to the temporary ban list for the Blocking Auto Expiration Time.

Enable Traffic Spike Control. Turns the spike limiter on. It is enabled by default and should stay on for any Internet-facing server.

Sampling Time Unit. The measurement window, in seconds. Requests are counted per source IP over this period. Very small values increase CPU overhead because counters are evaluated more often.

Max Requests. How many requests a single source IP may send per Sampling Time Unit before it is blocked. Set this low enough to catch floods but high enough to allow a busy but legitimate peer (see Best practices).

Address Removal Timeout. How long an IP’s request counter is kept in memory after its last request. A longer timeout means bursts spread over time still accumulate toward the limit, making evasion harder.

Blocking Auto Expiration Time. How long, in seconds, a blocked IP stays on the temporary ban list before it is automatically released.

Caching Table Size. Sizes the internal ban hash table, expressed as a power of two. The default is appropriate for almost all deployments; only change it on guidance from support.

Recommended tuning: keep Max Requests small and make Address Removal Timeout as long as practical, then add every known-good peer to Trusted IPs so their traffic is processed without any chance of being blocked. This gives you an aggressive limiter for unknown sources and zero risk of banning the sources you rely on.

Other Options

Enforce Domain. Accept registrations only for the domains configured in Domain and SSL Certificate. This rejects the large volume of scanner traffic that targets your IP address directly (with no valid domain), cutting attack noise significantly.

Log Rejected Requests. Write every rejected SIP request to /var/log/rejected_requests.log. Useful for short-term diagnosis of what is being blocked, but it can grow very large on a busy or heavily-attacked server. Enable it only while investigating, then turn it back off.

Best practices

  • Leave spike control enabled on any server reachable from the public Internet - it is one of the most effective defenses against SIP brute-force and flooding.
  • Trust before tightening. Add carriers, SBCs, and office IPs to Trusted IPs first, then you can safely lower Max Requests.
  • Enable Enforce Domain when all your endpoints register using one of your configured hostnames - it discards direct-to-IP scanner traffic cheaply.
  • Treat Log Rejected Requests as temporary. Do not leave it on in production; it fills the disk.
  • Review the Temporarily Banned IPs report periodically to confirm the limiter is catching abuse and not your own equipment.