Community discussions

MikroTik App
 
qaq2010
newbie
Topic Author
Posts: 25
Joined: Thu Feb 03, 2011 4:57 pm

Need Help with a sip conection and hacking

Sun Mar 10, 2013 10:58 pm

hello guys

so i got a mikrotik installed in my network and there is a DIA on it with a public ip and every thing works fine

so what i done is i assigned the public ip to my pbx server and its working fine and i can conect throw the pbx server from any where thro sip trunk

my problem is all the time i get my server online i get hacked with the sip trunks and the hackers just get me big bills

so i wannt to protect the pbx server the same time its online so the ppl can conect throw it with sip trunks but also protect it from getting hacked

what i was thinking is to change the port of conection on mikrotik for sip and map it with the original port on the pbx server

cose the hackers use somthing like sip port scan to find new pbx servers with sip unprotected


please advice guys
 
User avatar
jgellis
Member Candidate
Member Candidate
Posts: 139
Joined: Wed May 30, 2007 10:57 am
Location: USA

Re: Need Help with a sip conection and hacking

Mon Mar 11, 2013 7:06 am

Strong passwords on all trunks and extensions, NO EXCEPTIONS!
ACCEPT your SIP termination provider IPs through port 5060 if they do not use an outbound registration string.
DROP all other port 5060 traffic destined for your PBX.
If your IP phones are on the WAN instead of the LAN, use a VPN to bypass the above DROP rules and appear to come from internal.

Who is online

Users browsing this forum: karlisi, oskarsk, raiser, unhuzpt, vesuviustreamline and 121 guests