Вход | Регистрация
Вы здесь: Главная / Форум / Главный форум по Asterisk / TrixBox, Elastix, FreePbx / Elastix - странные вызовы с моего айпи

Elastix - странные вызовы с моего айпи

Звонки с айпи-адреса эластикса
Откуда: Ровно
Сообщений: 16

Elastix - странные вызовы с моего айпи

Добрый день!

За ночь появились вот такие странные записи в логе:

Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [0031#33155786056@from-sip-external:1] NoOp("SIP/m.y.i.p-b6c062c0", "Received incoming SIP connection from unknown peer to 0031#33155786056") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [0031#33155786056@from-sip-external:2] Set("SIP/m.y.i.p-b6c062c0", "DID=0031#33155786056") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [0031#33155786056@from-sip-external:3] Goto("SIP/m.y.i.p-b6c062c0", "s|1") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Goto (from-sip-external,s,1)
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@from-sip-external:1] GotoIf("SIP/m.y.i.p-b6c062c0", "1?from-trunk|0031#33155786056|1") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Goto (from-trunk,0031#33155786056,1)
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [0031#33155786056@from-trunk:1] NoOp("SIP/m.y.i.p-b6c062c0", "Catch-All DID Match - Found 0031#33155786056 - You probably want a DID for this.") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [0031#33155786056@from-trunk:2] Goto("SIP/m.y.i.p-b6c062c0", "ext-did|s|1") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Goto (ext-did,s,1)
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@ext-did:1] Set("SIP/m.y.i.p-b6c062c0", "__FROM_DID=s") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@ext-did:2] Gosub("SIP/m.y.i.p-b6c062c0", "app-blacklist-check|s|1") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@app-blacklist-check:1] LookupBlacklist("SIP/m.y.i.p-b6c062c0", "") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@app-blacklist-check:2] GotoIf("SIP/m.y.i.p-b6c062c0", "0?blacklisted") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@app-blacklist-check:3] Return("SIP/m.y.i.p-b6c062c0", "") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@ext-did:3] ExecIf("SIP/m.y.i.p-b6c062c0", "1 |Set|CALLERID(name)=6408622171676281138") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@ext-did:4] Set("SIP/m.y.i.p-b6c062c0", "__CALLINGPRES_SV=allowed_not_screened") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@ext-did:5] SetCallerPres("SIP/m.y.i.p-b6c062c0", "allowed_not_screened") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@ext-did:6] Goto("SIP/m.y.i.p-b6c062c0", "from-did-direct|101|1") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Goto (from-did-direct,101,1)
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [101@from-did-direct:1] Macro("SIP/m.y.i.p-b6c062c0", "exten-vm|novm|101") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:1] Macro("SIP/m.y.i.p-b6c062c0", "user-callerid") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:1] Set("SIP/m.y.i.p-b6c062c0", "AMPUSER=6408622171676281138") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:2] GotoIf("SIP/m.y.i.p-b6c062c0", "0?report") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: GotoIf
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:3] ExecIf("SIP/m.y.i.p-b6c062c0", "1|Set|REALCALLERIDNUM=6408622171676281138") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: ExecIf
Jan 11 00:42:58 DEBUG [7131] func_db.c:
DB: DEVICE/6408622171676281138/user not found in database.
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:4] Set("SIP/m.y.i.p-b6c062c0", "AMPUSER=") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 DEBUG [7131] func_db.c:
DB: AMPUSER//cidname not found in database.
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:5] Set("SIP/m.y.i.p-b6c062c0", "AMPUSERCIDNAME=") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:6] GotoIf("SIP/m.y.i.p-b6c062c0", "1?report") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Goto (macro-user-callerid,s,10)
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: GotoIf
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:10] GotoIf("SIP/m.y.i.p-b6c062c0", "0?continue") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: GotoIf
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:11] Set("SIP/m.y.i.p-b6c062c0", "__TTL=64") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:12] GotoIf("SIP/m.y.i.p-b6c062c0", "1?continue") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Goto (macro-user-callerid,s,19)
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: GotoIf
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-user-callerid:19] NoOp("SIP/m.y.i.p-b6c062c0", "Using CallerID "6408622171676281138" <6408622171676281138>") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Noop
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Macro
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:2] Set("SIP/m.y.i.p-b6c062c0", "RingGroupMethod=none") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:3] Set("SIP/m.y.i.p-b6c062c0", "VMBOX=novm") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:4] Set("SIP/m.y.i.p-b6c062c0", "EXTTOCALL=101") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:5] Set("SIP/m.y.i.p-b6c062c0", "CFUEXT=649") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 DEBUG [7131] func_db.c:
DB: CFB/101 not found in database.
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:6] Set("SIP/m.y.i.p-b6c062c0", "CFBEXT=") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:7] Set("SIP/m.y.i.p-b6c062c0", "RT=30") in new stack
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: Set
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:8] Macro("SIP/m.y.i.p-b6c062c0", "record-enable|101|IN") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-record-enable:1] GotoIf("SIP/m.y.i.p-b6c062c0", "1?check") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Goto (macro-record-enable,s,4)
Jan 11 00:42:58 DEBUG [7131] app_macro.c:
Executed application: GotoIf
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Executing [s@macro-record-enable:4] AGI("SIP/m.y.i.p-b6c062c0", "recordingcheck|20100111-004258|1263163378.502") in new stack
Jan 11 00:42:58 VERBOSE [7131] logger.c:
-- Launched AGI Script /var/lib/asterisk/agi-bin/recordingcheck
Jan 11 00:42:59 VERBOSE [7131] logger.c:
recordingcheck|20100111-004258|1263163378.502: Inbound recording enabled.
Jan 11 00:42:59 VERBOSE [7131] logger.c:
recordingcheck|20100111-004258|1263163378.502: CALLFILENAME=20100111-004258-1263163378.502
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- AGI Script recordingcheck completed, returning 0
Jan 11 00:42:59 DEBUG [7131] app_macro.c:
Executed application: AGI
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- Executing [s@macro-record-enable:999] MixMonitor("SIP/m.y.i.p-b6c062c0", "20100111-004258-1263163378.502.wav||") in new stack
Jan 11 00:42:59 DEBUG [7131] app_macro.c:
Executed application: MixMonitor
Jan 11 00:42:59 DEBUG [7131] app_macro.c:
Executed application: Macro
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- Executing [s@macro-exten-vm:9] Macro("SIP/m.y.i.p-b6c062c0", "dial|30|tT|101") in new stack
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- Executing [s@macro-dial:1] GotoIf("SIP/m.y.i.p-b6c062c0", "1?dial") in new stack
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- Goto (macro-dial,s,3)
Jan 11 00:42:59 DEBUG [7131] app_macro.c:
Executed application: GotoIf
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- Executing [s@macro-dial:3] AGI("SIP/m.y.i.p-b6c062c0", "dialparties.agi") in new stack
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- Launched AGI Script /var/lib/asterisk/agi-bin/dialparties.agi
Jan 11 00:42:59 VERBOSE [7133] logger.c:
== Begin MixMonitor Recording SIP/m.y.i.p-b6c062c0
Jan 11 00:42:59 VERBOSE [7131] logger.c:
dialparties.agi: Starting New Dialparties.agi
Jan 11 00:42:59 VERBOSE [7135] logger.c:
== Parsing '/etc/asterisk/manager.conf': [Jan 11 00:42:59] VERBOSE[7135] logger.c: Found
Jan 11 00:42:59 VERBOSE [7135] logger.c:
== Parsing '/etc/asterisk/manager_additional.conf': [Jan 11 00:42:59] VERBOSE[7135] logger.c: Found
Jan 11 00:42:59 VERBOSE [7135] logger.c:
== Parsing '/etc/asterisk/manager_custom.conf': [Jan 11 00:42:59] VERBOSE[7135] logger.c: Found
Jan 11 00:42:59 VERBOSE [7135] logger.c:
== Manager 'admin' logged on from 127.0.0.1
Jan 11 00:42:59 VERBOSE [7131] logger.c:
dialparties.agi: Caller ID name is '6408622171676281138' number is '6408622171676281138'
Jan 11 00:42:59 VERBOSE [7131] logger.c:
dialparties.agi: Methodology of ring is 'none'
Jan 11 00:42:59 VERBOSE [7131] logger.c:
-- dialparties.agi: Added extension 101 to extension map
Jan 11 00:42:59 VERBOSE [7131] logger.c:
> dialparties.agi: Extension 101 has call screening off

m.y.i.p = айпишник, на котором сидит эластикс. В записи - тишина. Не могу понять, откуда пришли звонки.
2010-01-11 13:02

Сообщений: 6521

Re: Elastix - странные вызовы с моего айпи

SIP/m.y.i.p-b6c062c0 - это спуф, подстановка SourceIP, чтобы заморочить. На самом деле простукивают на предмет allow anonymous call чтобы разведать диалплан и слить зарубежный трафик.
Наблюдаем на многих станциях.
2010-01-11 13:15

Avatara of SolarW
Откуда: Днепропетровск, Украина
Сообщений: 199

Re: Elastix - странные вызовы с моего айпи

А если "allow anonymous call = disable" - можно спать спокойно?

P.S. Кто-то подобными способами тыркался в подшефный трикс пару дней, потом попустило.
Так я думаю - успокоился или как? :-)
2010-01-12 18:24

Сообщений: 51

Re: Elastix - странные вызовы с моего айпи

ded
По умолчанию на cisco5300 открыто всё, т.е. слив может идти сразу п E1 PRI
Как правильно изначально сконфигурить циску буть то на access-list или же на прямую авторизацию ?
Речь среднее геометрическое между мыслью и действием!
2010-01-13 08:47

Откуда: Ровно
Сообщений: 16

Re: Elastix - странные вызовы с моего айпи

SolarW:

А если "allow anonymous call = disable" - можно спать спокойно?

P.S. Кто-то подобными способами тыркался в подшефный трикс пару дней, потом попустило.
Так я думаю - успокоился или как? :-)
У меня вроде перестали дёргать, но не могу принимать входящие без allow anonymous call.
2010-01-13 13:41

Сообщений: 6521

Re: Elastix - странные вызовы с моего айпи

nocture, можно и так, и эдак.
Если стоит в открытом космосе, то или ACL, или авторизация через sip-ua, если sip, или RAS, если Н.323.

vabue:

но не могу принимать входящие без allow anonymous call.
Самое время разобраться наконец с allow anonymous call? Уже пора.
2010-01-13 14:13

Добавить страницу в закладки:  Delicious Google Slashdot Yahoo Yandex.ru Reddit Digg Technorati Bobrdobr.ru Newsland.ru Smi2.ru Rumarkz.ru Vaau.ru Memori.ru Rucity.com Moemesto.ru News2.ru Mister-Wong.ru Myscoop.ru 100zakladok.ru