Send cisco-voip mailing list submissions to
        [email protected]

To subscribe or unsubscribe via the World Wide Web, visit
        https://puck.nether.net/mailman/listinfo/cisco-voip
or, via email, send a message with subject or body 'help' to
        [email protected]

You can reach the person managing the list at
        [email protected]

When replying, please edit your Subject line so it is more specific
than "Re: Contents of cisco-voip digest..."


Today's Topics:

   1. KEM Hotdial (Leslie Meade)
   2. Fwd: RTP permission and related attacks/threats (Ahmed -Y)
   3. Re: Fwd: RTP permission and related attacks/threats (Tim Smith)
   4.  dialing an ip address from cucm (Shaihan Jaffrey)


----------------------------------------------------------------------

Message: 1
Date: Fri, 11 Oct 2013 16:20:41 +0000
From: Leslie Meade <[email protected]>
To: "cisco-voip ([email protected])"
        <[email protected]>
Subject: [cisco-voip] KEM Hotdial
Message-ID:
        
<f64719604b4e6f41bdbb2af38e7609f44c1c5...@lvscgyex03.longviewsystems.com>
        
Content-Type: text/plain; charset="us-ascii"

Question,
Has anyone setup a KEM on a 8861 and configured hotdial on them ?
No matter what I try they have to press the pickup button for the call to work.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131011/233bfd71/attachment-0001.html>

------------------------------

Message: 2
Date: Fri, 11 Oct 2013 16:53:27 -0400
From: Ahmed -Y <[email protected]>
To: [email protected]
Subject: [cisco-voip] Fwd: RTP permission and related attacks/threats
Message-ID:
        <CAJEaoj9BT=qnnzp7-47mo1zbjl9x914wbr_y_tizmo87bh4...@mail.gmail.com>
Content-Type: text/plain; charset="iso-8859-1"

HI Guys,

I have to permit RTP traffic from internal network to other organizations
(under different management) on gateway devices (routers, switches). I am
curious to know if there are known attacks/threats when upd range
16384-32767 is permited. RTP source/destination can be desk phone or PC
with softphone. If yes then can we configure gateway routers/switches to
protect from these attacks.



We have cisco 7200, 6500, 3550, 3560, 3750 switches as gateway devices.



One more quick question are there only two ways (NBAR and ACL with udp
range) on routers/switches to identify/match RTP traffic? I know Firewalls
provide feature like inspect, AGL etc to dynamically identify RTP ports by
inspecting control traffic.



Your input will be highly appreciated



Regards
-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131011/390692ea/attachment-0001.html>

------------------------------

Message: 3
Date: Sat, 12 Oct 2013 10:41:33 +0000
From: Tim Smith <[email protected]>
To: Ahmed -Y <[email protected]>, "[email protected]"
        <[email protected]>
Subject: Re: [cisco-voip] Fwd: RTP permission and related
        attacks/threats
Message-ID:
        
<164ac709457347f4858b344008956...@hknpr04mb051.apcprd04.prod.outlook.com>
        
Content-Type: text/plain; charset="us-ascii"

Hi Ahmed,

When you say different organizations, do you mean other CUCM systems? SIP / 
H323 systems etc?
If so it's perfect use for CUBE and / or trusted relay points.

I would definitely not let other organizations right into my network on such a 
broad range of ports.
You should try and force them through a demarcation point that you can control.
You want the media to flow through this device. This way you only have to let 
them talk to your CUBE, and your CUBE can reach everyone inside your network on 
their behalf.

The other complication this gets around is NAT, and routing issues. I.e. 
without this type of setup, you would both have to have fairly full knowledge 
of each others networks, and also avoid overlaps.

It's been a while since I've looked at security on routers.
However, NBAR and ACL's are typically used in class maps in QoS to identify 
traffic and apply QoS policies

You do have inspection as an option on Cisco routers as well. Used to be called 
CBAC, I think it's just IOS Firewall now. It can inspect SIP, SCCP, H323 from 
memory, and open up pinholes where required.

My recommendation is look at some smart border device. I would be mandating SIP 
if possible and use CUBEs.

There are lots of improvements and fun stuff planned for the edge and this sort 
of connectivity coming soon too.

Hope that helps a bit.

Cheers,

Tim

From: cisco-voip [mailto:[email protected]] On Behalf Of Ahmed 
-Y
Sent: Saturday, 12 October 2013 7:53 AM
To: [email protected]
Subject: [cisco-voip] Fwd: RTP permission and related attacks/threats


HI Guys,

I have to permit RTP traffic from internal network to other organizations 
(under different management) on gateway devices (routers, switches). I am 
curious to know if there are known attacks/threats when upd range 16384-32767 
is permited. RTP source/destination can be desk phone or PC with softphone. If 
yes then can we configure gateway routers/switches to protect from these 
attacks.



We have cisco 7200, 6500, 3550, 3560, 3750 switches as gateway devices.



One more quick question are there only two ways (NBAR and ACL with udp range) 
on routers/switches to identify/match RTP traffic? I know Firewalls provide 
feature like inspect, AGL etc to dynamically identify RTP ports by inspecting 
control traffic.



Your input will be highly appreciated



Regards
-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131012/a6ab3815/attachment-0001.html>

------------------------------

Message: 4
Date: Sat, 12 Oct 2013 18:10:12 +0500
From: Shaihan Jaffrey <[email protected]>
To: Cisco VOIP <[email protected]>
Subject: [cisco-voip]  dialing an ip address from cucm
Message-ID:
        <capxwygrjowq9jmrmjzongprngs+5ew18bhqrgzk3wt6lgdx...@mail.gmail.com>
Content-Type: text/plain; charset="iso-8859-1"

My objective is to integrate a video conferencing gateway with cisco call
manager.
I've successfully created sip trunk between the video conferencing gateway
and cisco call manager. I can successfully dial extensions from cisco ip
phones to the video conferencing end points and vice versa.

Now the IVR of the video conferencing gateway is triggered by dialing an ip
address (a.b.c.d). As soon as a call is received on a.b.c.d the IVR of
video conferencing gateway starts playing.

How can i dial this ip address a.b.c.d from cisco call manager?

Regards
-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
<https://puck.nether.net/pipermail/cisco-voip/attachments/20131012/8c662566/attachment-0001.html>

------------------------------

Subject: Digest Footer

_______________________________________________
cisco-voip mailing list
[email protected]
https://puck.nether.net/mailman/listinfo/cisco-voip


------------------------------

End of cisco-voip Digest, Vol 120, Issue 12
*******************************************

Reply via email to