Trusted IPs
Trusted IPs is an allow-list of hosts and networks whose SIP traffic is always accepted, and which the platform will never automatically ban. Internet-facing SIP servers are constantly probed by scanners and brute-force tools, so the platform bans sources that fail authentication repeatedly or exceed traffic limits. That protection can misfire on your own infrastructure - a misconfigured desk phone that keeps retrying a bad password, or a carrier that bursts traffic - and lock out equipment you depend on. Adding those known-good sources here exempts them from both the Traffic Control spike limiter and automatic authentication banning.
The classic failure this prevents: one phone in the office has an old password cached, hammers the server with failed registrations, trips the auto-ban, and the ban applies to the office’s public IP - taking every phone behind that address offline. Trusting the office network keeps that from happening.
Trusted Addresses. Each entry is a single host IP address (for example 203.0.113.10) or a network address in CIDR notation (for example 203.0.113.0/24). Add one entry per line.
What belongs here
- Your SIP carrier / trunk provider signaling IPs, so a burst of legitimate call setups is never rate-limited.
- The public IP(s) of your own offices where phones register, so a single misbehaving device cannot get the whole site banned.
- Other Thirdlane servers in a cluster, and any monitoring or SBC hosts that legitimately send SIP to this server.
Best practices
- Be specific. Trust the narrowest range that covers the source - a single
/32host or the exact provider subnet - rather than broad blocks. A trusted address bypasses your automated defenses, so every entry is a hole you are deliberately opening. - Never trust
0.0.0.0/0or large public ranges. That disables spike control and auto-banning for the whole Internet. - Keep it current. Remove providers and offices you no longer use; a stale trusted entry is an unmonitored entry point.
- Trusting an address controls automatic banning only. You can still deliberately block a trusted-range host with a manual entry in Banned IPs if needed.
Related documentation
- Traffic Control - the spike limiter that trusted addresses bypass.
- Banned IPs - view and manage permanently banned addresses.
- Banned User Agents - block SIP clients by User-Agent string.