Skip to content

Trusted IPs

Trusted IPs is an allow-list of hosts and networks whose SIP traffic is always accepted, and which the platform will never automatically ban. Internet-facing SIP servers are constantly probed by scanners and brute-force tools, so the platform bans sources that fail authentication repeatedly or exceed traffic limits. That protection can misfire on your own infrastructure - a misconfigured desk phone that keeps retrying a bad password, or a carrier that bursts traffic - and lock out equipment you depend on. Adding those known-good sources here exempts them from both the Traffic Control spike limiter and automatic authentication banning.

The classic failure this prevents: one phone in the office has an old password cached, hammers the server with failed registrations, trips the auto-ban, and the ban applies to the office’s public IP - taking every phone behind that address offline. Trusting the office network keeps that from happening.

Trusted Addresses. Each entry is a single host IP address (for example 203.0.113.10) or a network address in CIDR notation (for example 203.0.113.0/24). Add one entry per line.

What belongs here

  • Your SIP carrier / trunk provider signaling IPs, so a burst of legitimate call setups is never rate-limited.
  • The public IP(s) of your own offices where phones register, so a single misbehaving device cannot get the whole site banned.
  • Other Thirdlane servers in a cluster, and any monitoring or SBC hosts that legitimately send SIP to this server.

Best practices

  • Be specific. Trust the narrowest range that covers the source - a single /32 host or the exact provider subnet - rather than broad blocks. A trusted address bypasses your automated defenses, so every entry is a hole you are deliberately opening.
  • Never trust 0.0.0.0/0 or large public ranges. That disables spike control and auto-banning for the whole Internet.
  • Keep it current. Remove providers and offices you no longer use; a stale trusted entry is an unmonitored entry point.
  • Trusting an address controls automatic banning only. You can still deliberately block a trusted-range host with a manual entry in Banned IPs if needed.