If there is no entry in the domain table, the it will error in the loose_route() function and the error message that I get is "403 Preload Route denied". When I add an entry to the domain table, it passes the loose_route() function and then error while authenticating. I have placed an xlog statement within the register block of the config file and right before the loose_route() function block is executed. I have included my config file.

thanks

Nathaniel

Eduardo Panciera wrote:
Are you sure that the message are been processed by a register block of your configuration? can you attach your configuration file? you can use log function in the differents blocks of your configuration , in order to clarify your debug. best regards.
Pancho.

On Mon, Jun 29, 2009 at 9:06 PM, Nathaniel L Keeling <[email protected] <mailto:[email protected]>> wrote:

    I am new and need an explanation. I have installed opensips 1.5 with
    database support. I am trying to authenticate via the subscriber's
    table. Utilizing the sample config file and uncommenting the areas to
    allow authentication via database, I try to register a sip device. I
    have added a user using opensipsctl. When the registration requests
    comes in, it dies in the loose_route() function with the error "403
    Preload Route Denied". According to the documentation on the
    loose_route() function, if there is no to-tag and there is only on
    route
    header indicating the localproxy, the function should return false. It
    is returning true. I then added the sip domain to the domain table and
    the error changes to "401Unauthorized". Please explain. I am including
    the SIP message and the debug output.

    Jun 29 01:15:03 [15473] DBG:core:parse_msg: SIP Request:
    Jun 29 01:15:03 [15473] DBG:core:parse_msg:  method:  <REGISTER>
    Jun 29 01:15:03 [15473] DBG:core:parse_msg:  uri:
    <sip:kwesi.chicagosip1.akan.us.com
    <http://kwesi.chicagosip1.akan.us.com/>>
    Jun 29 01:15:03 [15473] DBG:core:parse_msg:  version: <SIP/2.0>
    Jun 29 01:15:03 [15473] DBG:core:parse_headers: flags=2
    Jun 29 01:15:03 [15473] DBG:core:parse_via_param: found param type
    232,
    <branch> = <z9hG4bK728627284>; state=6
    Jun 29 01:15:03 [15473] DBG:core:parse_via_param: found param type
    235,
    <rport> = <n/a>; state=17
    Jun 29 01:15:03 [15473] DBG:core:parse_via: end of header reached,
    state=5
    Jun 29 01:15:03 [15473] DBG:core:parse_headers: via found, flags=2
    Jun 29 01:15:03 [15473] DBG:core:parse_headers: this is the first via
    Jun 29 01:15:03 [15473] DBG:core:receive_msg: After parse_msg...
    Jun 29 01:15:03 [15473] DBG:core:receive_msg: preparing to run routing
    scripts...
    Jun 29 01:15:03 [15473] DBG:core:parse_headers: flags=100
    Jun 29 01:15:03 [15473] DBG:core:parse_to: end of header reached,
    state=10
    Jun 29 01:15:03 [15473] DBG:core:parse_to: display={},
    ruri={sip:[email protected]
    <mailto:sip%[email protected]>}
    Jun 29 01:15:03 [15473] DBG:core:get_hdr_field: <To> [48];
    uri=[sip:[email protected]
    <mailto:sip%[email protected]>]
    Jun 29 01:15:03 [15473] DBG:core:get_hdr_field: to body
    [<sip:[email protected]
    <mailto:sip%[email protected]>>
    ]
    Jun 29 01:15:03 [15473] DBG:core:get_hdr_field: cseq <CSeq>: <6493>
    <REGISTER>
    Jun 29 01:15:03 [15473] DBG:maxfwd:is_maxfwd_present: value = 70
    Starting to process request................
    Jun 29 01:15:03 [15473] DBG:uri:has_totag: no totag
    we are about to check for cancel................
    Jun 29 01:15:03 [15473] DBG:core:parse_headers: flags=78
    Jun 29 01:15:03 [15473] DBG:tm:t_lookup_request: start searching:
    hash=15692, isACK=0
    Jun 29 01:15:03 [15473] DBG:tm:matching_3261: RFC3261 transaction
    matching failed
    Jun 29 01:15:03 [15473] DBG:tm:t_lookup_request: no transaction found
    we are about to check registration and multidomain................
    we are about to check for loose route................
    Jun 29 01:15:03 [15473] DBG:core:parse_headers: flags=200
    Jun 29 01:15:03 [15473] DBG:rr:is_preloaded: is_preloaded: Yes
    Jun 29 01:15:03 [15473] DBG:core:grep_sock_info: checking if host==us:
    29==14 &&  [kwesi.chicagosip1.akan.us.com
    <http://kwesi.chicagosip1.akan.us.com/>] == [209.252.110.37]
    Jun 29 01:15:03 [15473] DBG:core:grep_sock_info: checking if port 5060
    matches port 5060
    Jun 29 01:15:03 [15473] DBG:core:check_self: host != me
    Jun 29 01:15:03 [15473] DBG:rr:after_loose: Topmost URI is NOT myself
    Jun 29 01:15:03 [15473] DBG:rr:after_loose: URI to be processed:
    'sip:kwesi.chicagosip1.akan.us.com:5060;lr'
    Jun 29 01:15:03 [15473] DBG:rr:after_loose: Next URI is a loose router
    Jun 29 01:15:03 [15473] DBG:core:parse_to_param: tag=1590215359
    Jun 29 01:15:03 [15473] DBG:core:parse_to: end of header reached,
    state=29
    Jun 29 01:15:03 [15473] DBG:core:parse_to: display={},
    ruri={sip:[email protected]
    <mailto:sip%[email protected]>}
    Attempt to route with preloaded Route's

    
[sip:[email protected]/sip:[email protected]/sip:kwesi.chicagosip1.akan.us.com/[email protected]]jun
    
<http://sip:[email protected]/sip:[email protected]/sip:kwesi.chicagosip1.akan.us.com/[email protected]%5djun>
    29

    01:15:03 [15473] DBG:core:parse_headers: flags=ffffffffffffffff
    Jun 29 01:15:03 [15473] DBG:core:get_hdr_field: content_length=0
    Jun 29 01:15:03 [15473] DBG:core:get_hdr_field: found end of header
    Jun 29 01:15:03 [15473] DBG:core:check_via_address: params
    98.122.86.123, 98.122.86.123, 0
    Jun 29 01:15:03 [15473] DBG:core:destroy_avp_list: destroying list 0
    Jun 29 01:15:03 [15473] DBG:core:receive_msg: cleaning up


    #
    U 2009/06/29 01:35:01.608581 98.122.86.123:6062
    <http://98.122.86.123:6062/> -> 209.252.110.37:5060
    <http://209.252.110.37:5060/>
    REGISTER sip:kwesi.chicagosip1.akan.us.com
    <http://kwesi.chicagosip1.akan.us.com/> SIP/2.0.
    Via: SIP/2.0/UDP 98.122.86.123:6062;branch=z9hG4bK1362945809;rport.
    Route: <sip:kwesi.chicagosip1.akan.us.com:5060;lr>.
    From: <sip:[email protected]
    <mailto:sip%[email protected]>>;tag=1590215359.
    To: <sip:[email protected]
    <mailto:sip%[email protected]>>.
    Call-ID: [email protected]
    <mailto:[email protected]>.
    CSeq: 6494 REGISTER.
    Contact:
    <sip:[email protected]:6062
    
<http://sip:[email protected]:6062>>;reg-id=2;+sip.instance="<urn:uuid:00000000-0000-1000-8000-000B821473A2>".
    Max-Forwards: 70.
    User-Agent: Grandstream GXW-4004  V1.3A 1.0.1.15.
    Supported: path.
    Expires: 3600.
    Allow: INVITE, ACK, OPTIONS, CANCEL, BYE, SUBSCRIBE, NOTIFY, INFO,
    REFER, UPDATE.
    Content-Length: 0.
    .

    #
    U 2009/06/29 01:35:01.633256 209.252.110.37:5060
    <http://209.252.110.37:5060/> -> 98.122.86.123:6062
    <http://98.122.86.123:6062/>
    SIP/2.0 403 Preload Route denied.
    Via: SIP/2.0/UDP
    98.122.86.123:6062;branch=z9hG4bK1362945809;rport=6062.
    From: <sip:[email protected]
    <mailto:sip%[email protected]>>;tag=1590215359.
    To:
    <sip:[email protected]
    
<mailto:sip%[email protected]>>;tag=d3ff5fc5ce3916ee69f721c7781603d2.2cfe.
    Call-ID: [email protected]
    <mailto:[email protected]>.
    CSeq: 6494 REGISTER.
    Server: OpenSIPS (1.5.1-tls (sparc64/solaris)).
    Content-Length: 0.


    Thanks

    Nathaniel

    _______________________________________________
    Users mailing list
    [email protected] <mailto:[email protected]>
    http://lists.opensips.org/cgi-bin/mailman/listinfo/users




--
Eduardo Panciera
------------------------------------------------------------------------


No virus found in this incoming message.
Checked by AVG - www.avg.com Version: 8.5.375 / Virus Database: 270.12.94/2208 - Release Date: 06/29/09 05:54:00

#
# $Id: opensips.cfg 5503 2009-03-22 16:22:32Z bogdan_iancu $
#
# OpenSIPS basic configuration script
#     by Anca Vamanu <[email protected]>
#
# Please refer to the Core CookBook at:
#      http://www.opensips.org/index.php?n=Resources.DocsCookbooks
# for a explanation of possible statements, functions and parameters.
#


####### Global Parameters #########

debug=6
log_stderror=yes
log_facility=LOG_LOCAL0
log_stderror=yes

fork=no
children=4

/* uncomment the following lines to enable debugging */
#debug=6
#fork=no
#log_stderror=yes

/* uncomment the next line to disable TCP (default on) */
#disable_tcp=yes

/* uncomment the next line to enable the auto temporary blacklisting of
   not available destinations (default disabled) */
#disable_dns_blacklist=no

/* uncomment the next line to enable IPv6 lookup after IPv4 dns
   lookup failures (default disabled) */
#dns_try_ipv6=yes

/* uncomment the next line to disable the auto discovery of local aliases
   based on revers DNS on IPs (default on) */
#auto_aliases=no

/* uncomment the following lines to enable TLS support  (default off) */
#disable_tls = no
#listen = tls:your_IP:5061
#tls_verify_server = 1
#tls_verify_client = 1
#tls_require_client_certificate = 0
#tls_method = TLSv1
#tls_certificate = "/data/opensips/etc/opensips/tls/user/user-cert.pem"
#tls_private_key = "/data/opensips/etc/opensips/tls/user/user-privkey.pem"
#tls_ca_list = "/data/opensips/etc/opensips/tls/user/user-calist.pem"


port=5060

/* uncomment and configure the following line if you want opensips to
   bind on a specific interface/port/proto (default bind on all available) */
listen=udp:209.252.110.37:5060


####### Modules Section ########

#set module path
mpath="/data/opensips/lib64/opensips/modules/"

/* uncomment next line for MySQL DB support */
#loadmodule "db_mysql.so"
loadmodule "db_postgres.so"
loadmodule "signaling.so"
loadmodule "sl.so"
loadmodule "tm.so"
loadmodule "rr.so"
loadmodule "maxfwd.so"
loadmodule "usrloc.so"
loadmodule "registrar.so"
loadmodule "textops.so"
loadmodule "mi_fifo.so"
loadmodule "uri_db.so"
loadmodule "uri.so"
loadmodule "xlog.so"
loadmodule "acc.so"

#
/* uncomment next lines for MySQL based authentication support
   NOTE: a DB (like db_mysql) module must be also loaded */

loadmodule "auth.so"
loadmodule "auth_db.so"

/* uncomment next line for aliases support
   NOTE: a DB (like db_mysql) module must be also loaded */

loadmodule "alias_db.so"

/* uncomment next line for multi-domain support
   NOTE: a DB (like db_mysql) module must be also loaded
   NOTE: be sure and enable multi-domain support in all used modules
         (see "multi-module params" section ) */

loadmodule "domain.so"

/* uncomment the next two lines for presence server support
   NOTE: a DB (like db_mysql) module must be also loaded */

#loadmodule "presence.so"
#loadmodule "presence_xml.so"


# ----------------- setting module-specific parameters ---------------


# ----- mi_fifo params -----
modparam("mi_fifo", "fifo_name", "/tmp/opensips_fifo")


##            ----- rr params -----            ##
#
# add value to ;lr param to cope with most of the UAs
modparam("rr", "enable_full_lr", 1)

# do not append from tag to the RR (no need for this script)
modparam("rr", "append_fromtag", 0)


##         ----- registrar params -----        ##
#
modparam("registrar", "method_filtering", 1)

/* uncomment the next line to disable parallel forking via location */

# modparam("registrar", "append_branches", 0)

/* uncomment the next line not to allow more than 10 contacts per AOR */

#modparam("registrar", "max_contacts", 10)


##          ----- usrloc params -----          ##
#
/* uncomment the following lines if you want to enable DB persistency
   for location entries */

modparam("usrloc", "db_mode",   2)
modparam("usrloc", "db_url",
        "postgres://opensips:opensip...@localhost/opensips")


##          ----- uri_db params -----          ##
#
/* by default we disable the DB support in the module as we do not need it
   in this configuration */

modparam("uri_db", "use_uri_table", 0)
modparam("uri_db", "db_url", 
"postgres://opensips:opensip...@localhost/opensips")


##            ----- acc params -----           ##
#
/* what sepcial events should be accounted ? */

modparam("acc", "early_media", 1)
modparam("acc", "report_ack", 1)
modparam("acc", "report_cancels", 1)

/* by default ww do not adjust the direct of the sequential requests.
   if you enable this parameter, be sure the enable "append_fromtag"
   in "rr" module */

modparam("acc", "detect_direction", 0)

/* account triggers (flags) */

modparam("acc", "failed_transaction_flag", 3)
modparam("acc", "log_flag", 1)
modparam("acc", "log_missed_flag", 2)

/* uncomment the following lines to enable DB accounting also */

modparam("acc", "db_flag", 1)
modparam("acc", "db_missed_flag", 2)


##         ----- auth_db params -----          ##
#
/* uncomment the following lines if you want to enable the DB based
   authentication */

modparam("auth_db", "calculate_ha1", yes)
modparam("auth_db", "password_column", "password")
modparam("auth_db", "db_url",
        "postgres://opensips:opensip...@localhost/opensips")
modparam("auth_db", "load_credentials", "")


##         ----- alias_db params -----         ##
#
/* uncomment the following lines if you want to enable the DB based
   aliases */

modparam("alias_db", "db_url",
        "postgres://opensips:opensip...@localhost/opensips")


##          ----- domain params -----          ##
#
/* uncomment the following lines to enable multi-domain detection
   support */

modparam("domain", "db_url",
        "postgres://opensips:opensip...@localhost/opensips")
modparam("domain", "db_mode", 1)   # Use caching


##       ----- multi-module params -----       ##
#
/* uncomment the following line if you want to enable multi-domain support
   in the modules (dafault off) */

modparam("alias_db|auth_db|usrloc|uri_db", "use_domain", 1)



##         ----- presence params -----         ##
#
/* uncomment the following lines if you want to enable presence */

#modparam("presence|presence_xml", "db_url",
#       "postgres://opensips:opensip...@localhost/opensips")
#modparam("presence_xml", "force_active", 1)
#modparam("presence", "server_address", "sip:192.168.1.2:5060")


####### Routing Logic ########


# main request routing logic

route{

        if (!mf_process_maxfwd_header("10")) {
                sl_send_reply("483","Too Many Hops");
                exit;
        }

 xlog("Starting to process request................\n");
        if (has_totag()) {
                # sequential request withing a dialog should
                # take the path determined by record-routing
                if (loose_route()) {
                        if (is_method("BYE")) {
                                setflag(1); # do accounting ...
                                setflag(3); # ... even if the transaction fails
                        } else if (is_method("INVITE")) {
                                # even if in most of the cases is useless, do 
RR for
                                # re-INVITEs alos, as some buggy clients do 
change route set
                                # during the dialog.
                                record_route();
                        }
                        # route it out to whatever destination was set by 
loose_route()
                        # in $du (destination URI).
                        route(1);
                } else {
                        /* uncomment the following lines if you want to enable 
presence */
                        ##if (is_method("SUBSCRIBE") && $rd == 
"your.server.ip.address") {
                        ##      # in-dialog subscribe requests
                        ##      route(2);
                        ##      exit;
                        ##}
                        if ( is_method("ACK") ) {
                                if ( t_check_trans() ) {
                                        # non loose-route, but stateful ACK; 
must be an ACK after
                                        # a 487 or e.g. 404 from upstream server
                                        t_relay();
                                        exit;
                                } else {
                                        # ACK without matching transaction ->
                                        # ignore and discard
                                        exit;
                                }
                        }
                        sl_send_reply("404","Not here");
                }
                exit;
        }

        #initial requests

        # CANCEL processing
 xlog("we are about to check for cancel................\n");
        if (is_method("CANCEL"))
        {
                if (t_check_trans())
                        t_relay();
                exit;
        }

        t_check_trans();

        # authenticate if from local subscriber (uncomment to enable auth)
        # authenticate all initial non-REGISTER request that pretend to be
        # generated by local subscriber (domain from FROM URI is local)
        if (!(method=="REGISTER") && from_uri==myself) /*no multidomain 
version*/
        ##if (!(method=="REGISTER") && is_from_local())  /*multidomain version*/
        {
                if (!proxy_authorize("", "subscriber")) {
                        proxy_challenge("", "0");
                        exit;
                }
                if (!check_from()) {
                        sl_send_reply("403","Forbidden auth ID");
                        exit;
                }
          
                consume_credentials();
                # caller authenticated
          }

        # preloaded route checking
 xlog("we are about to check for loose route................\n");
        if (loose_route()) {
                xlog("L_ERR",
                "Attempt to route with preloaded Route's [$fu/$tu/$ru/$ci]");
                if (!is_method("ACK"))
                        sl_send_reply("403","Preload Route denied");
                exit;
        }

        # record routing
 xlog("we are about to record route................\n");
        if (!is_method("REGISTER|MESSAGE"))
                record_route();

        # account only INVITEs
        if (is_method("INVITE")) {
                setflag(1); # do accounting
        }
        if (!uri==myself)
        ## replace with following line if multi-domain support is used
        ##if (!is_uri_host_local())
        {
                append_hf("P-hint: outbound\r\n");
                # if you have some interdomain connections via TLS
                ##if($rd=="tls_domain1.net") {
                ##      t_relay("tls:domain1.net");
                ##      exit;
                ##} else if($rd=="tls_domain2.net") {
                ##      t_relay("tls:domain2.net");
                ##      exit;
                ##}
                route(1);
        }

        # requests for my domain

        ## uncomment this if you want to enable presence server
        ##   and comment the next 'if' block
        ##   NOTE: uncomment also the definition of route[2] from  below
        ##if( is_method("PUBLISH|SUBSCRIBE"))
        ##              route(2);

        if (is_method("PUBLISH"))
        {
                sl_send_reply("503", "Service Unavailable");
                exit;
        }


        if (is_method("REGISTER"))
        {
                # authenticate the REGISTER requests (uncomment to enable auth)
  xlog("we have a register request................\n");
                if (!www_authorize("", "subscriber"))
                {
                        www_challenge("", "0");
                        exit;
                }

                if (!check_to())
                {
                        sl_send_reply("403","Forbidden auth ID");
                        exit;
                }

                if (!save("location"))
                        sl_reply_error();

                exit;
        }

        if ($rU==NULL) {
                # request with no Username in RURI
                sl_send_reply("484","Address Incomplete");
                exit;
        }

        # apply DB based aliases (uncomment to enable)
        alias_db_lookup("dbaliases");

        if (!lookup("location")) {
                switch ($retcode) {
                        case -1:
                        case -3:
                                t_newtran();
                                t_reply("404", "Not Found");
                                exit;
                        case -2:
                                sl_send_reply("405", "Method Not Allowed");
                                exit;
                }
        }

        # when routing via usrloc, log the missed calls also
        setflag(2);

        route(1);
}


route[1] {
        # for INVITEs enable some additional helper routes
        if (is_method("INVITE")) {
                t_on_branch("2");
                t_on_reply("2");
                t_on_failure("1");
        }

        if (!t_relay()) {
                sl_reply_error();
        };
        exit;
}


# Presence route
/* uncomment the whole following route for enabling presence
   NOTE: do not forget to enable the call of this route from the main
     route */
##route[2]
##{
##      if (!t_newtran())
##      {
##              sl_reply_error();
##              exit;
##      };
##
##      if(is_method("PUBLISH"))
##      {
##              handle_publish();
##              t_release();
##      }
##      else
##      if( is_method("SUBSCRIBE"))
##      {
##              handle_subscribe();
##              t_release();
##      }
##
##      exit;
##}


branch_route[2] {
        xlog("new branch at $ru\n");
}


onreply_route[2] {
        xlog("incoming reply\n");
}


failure_route[1] {
        if (t_was_cancelled()) {
                exit;
        }

        # uncomment the following lines if you want to block client
        # redirect based on 3xx replies.
        ##if (t_check_status("3[0-9][0-9]")) {
        ##t_reply("404","Not found");
        ##      exit;
        ##}

        # uncomment the following lines if you want to redirect the failed
        # calls to a different new destination
        ##if (t_check_status("486|408")) {
        ##      sethostport("192.168.2.100:5060");
        ##      # do not set the missed call flag again
        ##      t_relay();
        ##}
}

_______________________________________________
Users mailing list
[email protected]
http://lists.opensips.org/cgi-bin/mailman/listinfo/users

Reply via email to