Monday, August 27, 2012

Some security tips for Asterisk deployment

Unless your Asterisk server is purely for internal use, you will
inevitably face the potential threats from hackers who look for security
loopholes to abuse your system.

Here are some protection measures that we should consider.

1. Disallow guest call unless you really need it

In the [general] section of sip.conf, set allowguest=no

2. Always reject with '401 Unauthorized' for unauthorized INVITE or
REGISTER, instead of letting the requester know whether there was a
matching peer.

In [general] section of sip.conf, set alwaysauthreject = yes

3. Make use of permit= and deny= in sip peer definition to restrict
which clients we will accept.

4. Empty the [default] context

5. We always use strong password in our sip entities.

6. If we really need to enable AMI on a public ip address, make use of
the permit and deny to restrict which client can access Asterisk via AMI.

7. Sip username should be different from the extensions. That would
make guessing less easy.

8. Deploy iptables and fail2ban. We can then monitor the asterisk log
file to spot intruders and block them accordingly.

9. We can also change the port (default 5060) that Asterisk listens to.
(bindport=5060 in sip.conf). This approach applies when we only need
to handle known peers such as branch offices or remote extensions.

2 comments:


  1. Thank you very much for your information.
    Australia ETA/eVisitor Visa
    is quiet easy to apply online from Singapore,
    Malaysia, United Kingdom, United States, Canada, France and including all others ETA Eligible Countries from our website.

    ReplyDelete
  2. Very good article and I like it. Thank you for giving me information

    Please Visit to mboplay888.com Slot gambling agent, ball, live casino Indonesia

    Nikmati bonus menarik dari MBOPLAY :

    Welcome Bonus New Member 20% ALL GAMES [ BOLA, POKER, LIVE CASINO, SLOT, IDN LIVE ]

    Promo Cashback Mingguan BOLA UP TO 7.5%
    Promo Cashback Mingguan BOLA UP TO SLOT 1%
    Promo Cashback Mingguan BOLA UP TO LIVE CASINO 1%
    Bonus Next Deposit 5% [ BOLA, LIVE CASINO, SLOT, IDN LIVE ]
    Komisi IDNPOKER 0.5%

    MBOPLAY
    SPBO BOLA
    AGEN SBOBET
    BANDAR JUDI
    AGEN IDN SPORTS
    BURSA TARUHAN BOLA
    JUDI BOLA TERPERCAYA
    BANDAR SPORTS ONLINE TERPERCAYA

    Contact us MBOPLAY.COM :
    Livechat : https://mboplay88b.com/?ref=daftar
    Whatsapp : +6282117858228

    Link Alternatif MBOPLAY :

    https://mboplay88b.com/?ref=daftar
    https://mboplay88c.com/?ref=daftar
    https://mboplay888.com/?ref=daftar

    ReplyDelete