[Spce-user] allowed_clis not working properly

Stefano Rogna Manassero di Costigliole stefanormc at gmail.com
Sat Jul 17 06:43:27 EDT 2021


Hello Marco,

Thanks for the suggestions; the problem with NCOS is that in some cases
(like this one) call is directed toward Monaco Telecom Mobile number that
is costly but legit, so I cannot blacklist it.

This is the complete log not grepped:

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Call from PSTN - R=«
sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Inbound peering group '6' matched,
looking up peer host - R=«sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Selected peering host id '8' as
inbound peer - R=«sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Dialog managed, lua_dlg_callid:[«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1»] - R=«
sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: User-Provided CLI '«0691516096»'
taken from From-User as fallback, should be from 'pai_user' - R=«
sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Network-Provided CLI '«0691516096»'
taken from From-User as fallback, should be from 'pai_user' - R=«
sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting
'«0691516096»@«213.204.31.10»' as initiating user-provided CLI - R=«
sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting
'«0691516096»@«213.204.31.10»' as initiating network-provided CLI - R=«
sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Rewriting called party
'«0122622461»' to '«390122622461»' - R=«sip:0122622461 at 94.125.235.56» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Callee was aliased with base
'«390122622461»' - R=«sip:0122622461 at c.voceblu.it» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Callee is local,
uuid='«d0019f4a-285a-47ee-b7fd-46fcbdd68586»' - R=«
sip:0122622461 at c.voceblu.it» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting acc source-leg for uuid
'«0»':
'«0|0691516096|213.204.31.10|0691516096|||0|||0|call|213.204.31.10|1626364842.551728||||||||||||0691516096||||||8|»'
- R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting acc destination-leg for
uuid '«d0019f4a-285a-47ee-b7fd-46fcbdd68586»':
'«0||2682|321|0122622461|d0019f4a-285a-47ee-b7fd-46fcbdd68586|0122622461|
c.voceblu.it|390122622461|94.125.235.56|0||||||||||||0122622461|||»' -
R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting
caller_cli_userprov/caller_domain_userprov '«0691516096»@«c.voceblu.it»'
for upn - R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting From to '<«
sip:0691516096 at c.voceblu.it»>' - R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting
caller_cli_netprov/caller_domain_netprov '«0691516096»@«c.voceblu.it»' for
npn - R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting PAI to '<«
sip:0691516096 at c.voceblu.it»>' - R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Setting P-Called-Party-ID
'<sip:«0122622461»@«c.voceblu.it»>' - R=«sip:0122622461 at 94.125.233.34:5060»
ID=«0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1»
UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Appending P-D-URI '«sip:lb at 127.0.0.1
;lr;socket=sip:94.125.235.56:5060;ngcpdevid=0122622461»' -
R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Forcing request via B2BUA
'«sip:127.0.0.1:5080»' - R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: Request leaving server, M=INVITE
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5080»' -
R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1743]: NOTICE: <script>: New reply on proxy - ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1743]: NOTICE: <script>: NAT-Reply - S=100 - Connecting
M=INVITE IP=«213.204.31.10»:«5060» («127.0.0.1»:«5080») ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'
DESTIP=«127.0.0.1»:«5062»

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1740]: NOTICE: <script>: New reply on proxy - ID=«
abcd31f5-03564654-1d07bf1 at 127.0.0.1» UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: New reply on proxy - ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: NAT-Reply - S=302 - Moved
Temporarily M=INVITE IP=«213.204.31.10»:«5060» («127.0.0.1»:«5080») ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'
DESTIP=«127.0.0.1»:«5062»

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: HDR: Skip apply because redirect
301 or 302 - ID=«0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1»
UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Sending reply S=302 M=INVITE
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«<null>»' - ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Failure route for local call,
code='302' - R=«sip:0122622461 at 94.125.233.34:5060» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Redirect from UAC to
'«00377630547760»:«c.voceblu.it»' intercepted - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Callee is not local - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Call to SIP Peering - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Load gws matching calling part '«
sip:0691516096 at c.voceblu.it»' and called user '«00377630547760»' and called
part '«sip:00377630547760 at c.voceblu.it;transport=udp»' - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1754]: NOTICE: <script>: New request on proxy - M=REGISTER
R=«sip:94.125.235.56» F=«sip:1111pass at 94.125.235.56» T=«
sip:1111pass at 94.125.235.56» IP=«89.239.33.252»:«10128» («127.0.0.1»:«5060»)
ID=«141d7e-959a749b2fd352d0-83d75088 at 94.125.235.56»
UA='VaxSIPUserAgent/3.5' DESTIP=«127.0.0.1»:«5062»

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1754]: NOTICE: <script>: Sending reply S=100 Trying
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5060»' - R=«sip:94.125.235.56» ID=«
141d7e-959a749b2fd352d0-83d75088 at 94.125.235.56» UA='VaxSIPUserAgent/3.5'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1754]: WARNING: <script>: Domain not served here -
R=«sip:94.125.235.56» ID=«141d7e-959a749b2fd352d0-83d75088 at 94.125.235.56»
UA='VaxSIPUserAgent/3.5'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1754]: NOTICE: <script>: Sending reply S=403 Domain not
served here fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5060»' -
R=«sip:94.125.235.56» ID=«141d7e-959a749b2fd352d0-83d75088 at 94.125.235.56»
UA='VaxSIPUserAgent/3.5'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <core> [core/action.c:1589]: run_actions():
alert - action [lcr_rate (26)] cfg [/etc/kamailio/proxy/proxy.cfg:8493]
took too long [203310 us]

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting acc source-leg for uuid
'«d0019f4a-285a-47ee-b7fd-46fcbdd68586»':
'«d0019f4a-285a-47ee-b7fd-46fcbdd68586|0122622461|c.voceblu.it|390122622461||2682|321|||<null>|cfb|213.204.31.10|1626364842.837492||||||||||||390122622461||||||8|»'
- R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Rewriting acc called party
'«00377630547760»' to '«377630547760»' - R=«sip:00377630547760 at 213.204.30.51»
ID=«0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1»
UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting acc destination-leg for
uuid '«0»':
'«0|||0|00377630547760|0|00377630547760|213.204.30.51|00377630547760|
c.voceblu.it|3||||||||||||377630547760|||»' - R=«
sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting
caller_cli_userprov/caller_domain_userprov '«0691516096»@«213.204.31.10»'
for upn - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting From to '<«
sip:0691516096 at 213.204.31.10»>' - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting
caller_cli_userprov/caller_domain_userprov '«0691516096»@«213.204.31.10»'
for upn - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting PAI to '<«
sip:0691516096 at 213.204.31.10»>' - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Rewriting called party
'«00377630547760»' to '«377630547760»' - R=«sip:00377630547760 at 213.204.30.51»
ID=«0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1»
UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting P-Called-Party-ID
'<sip:«377630547760»@«213.204.30.51»>' - R=«sip:377630547760 at 213.204.30.51»
ID=«0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1»
UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting
'sip:«213.204.30.51»:«5060»' taken from D-URI as next hop after lb for PSTN
call - R=«sip:377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Appending P-D-URI
'«sip:127.0.0.1:5060;received=sip:213.204.30.51:5060%3blr%3btransport%3dudp»'
- R=«sip:377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Forcing request via B2BUA
'«sip:127.0.0.1:5080»' - R=«sip:377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Dropping local branch - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Request leaving server, M=INVITE
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5080»' - R=«
sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1748]: NOTICE: <script>: New reply on proxy - ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1748]: NOTICE: <script>: NAT-Reply - S=100 - Connecting
M=INVITE IP=«213.204.31.10»:«5060» («127.0.0.1»:«5080») ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'
DESTIP=«127.0.0.1»:«5062»

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1752]: NOTICE: <script>: New reply on proxy - ID=«
abcd31f5-11fd3654-1d07bf1 at 127.0.0.1» UA='Grandstream GXP1610 1.0.4.67'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1745]: NOTICE: <script>: New reply on proxy - ID=«
abcd31f5-6f9b3654-1d07bf1 at 127.0.0.1» UA='A510 IP/42.199.00.000.000'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1735]: NOTICE: <script>: New reply on proxy - ID=«
abcd31f5-5f9b3654-1d07bf1 at 127.0.0.1» UA='AS690 IP/42.248.00.000.000'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1743]: NOTICE: <script>: New reply on proxy - ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1743]: NOTICE: <script>: NAT-Reply - S=183 - Progress
M=INVITE IP=«213.204.31.10»:«5060» («127.0.0.1»:«5080») ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'
DESTIP=«127.0.0.1»:«5062»

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1743]: NOTICE: <script>: Sending reply S=183 M=INVITE
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«<null>»' - ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='<null>'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1740]: NOTICE: <script>: New request on proxy - M=REGISTER
R=«sip:94.125.235.56» F=«sip:66 at 94.125.235.56» T=«sip:66 at 94.125.235.56»
IP=«89.239.33.252»:«20333» («127.0.0.1»:«5060») ID=«
141fc0-19e67234e6abfa3-d1215200 at 94.125.235.56» UA='VaxSIPUserAgent/3.5'
DESTIP=«127.0.0.1»:«5062»

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1740]: NOTICE: <script>: Sending reply S=100 Trying
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5060»' - R=«sip:94.125.235.56» ID=«
141fc0-19e67234e6abfa3-d1215200 at 94.125.235.56» UA='VaxSIPUserAgent/3.5'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1740]: WARNING: <script>: Domain not served here -
R=«sip:94.125.235.56» ID=«141fc0-19e67234e6abfa3-d1215200 at 94.125.235.56»
UA='VaxSIPUserAgent/3.5'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1740]: NOTICE: <script>: Sending reply S=403 Domain not
served here fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5060»' -
R=«sip:94.125.235.56» ID=«141fc0-19e67234e6abfa3-d1215200 at 94.125.235.56»
UA='VaxSIPUserAgent/3.5'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1754]: NOTICE: <script>: New request on proxy - M=NOTIFY
R=«sip:centrale.avanzati.it» F=«sip:0173730250 at d.voceblu.it» T=«sip:
centrale.avanzati.it» IP=«172.16.29.143»:«5060» («127.0.0.1»:«5060») ID=«
56500368-b1f2d5d2 at 192.168.1.81» UA='Cisco/SPA122-1.3.5(004p)'
DESTIP=«127.0.0.1»:«5062»

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1754]: NOTICE: <script>: Sending reply S=100 Trying
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5060»' - R=«sip:
centrale.avanzati.it» ID=«56500368-b1f2d5d2 at 192.168.1.81»
UA='Cisco/SPA122-1.3.5(004p)'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1754]: NOTICE: <script>: Handling RLS notification  - R=«sip:
centrale.avanzati.it» ID=«56500368-b1f2d5d2 at 192.168.1.81»
UA='Cisco/SPA122-1.3.5(004p)'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1754]: ERROR: rls [resource_notify.c:591]:
ki_rls_handle_notify(): to tag value not parsed

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1754]: NOTICE: <script>: Failed to handle RLS notification -
R=«sip:centrale.avanzati.it» ID=«56500368-b1f2d5d2 at 192.168.1.81»
UA='Cisco/SPA122-1.3.5(004p)'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1754]: NOTICE: <script>: Sending reply S=404 Failed
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5060»' - R=«sip:
centrale.avanzati.it» ID=«56500368-b1f2d5d2 at 192.168.1.81»
UA='Cisco/SPA122-1.3.5(004p)'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1737]: NOTICE: <script>: New reply on proxy - ID=«
abcd31f5-c9734654-1d07bf1 at 127.0.0.1» UA='A540 IP/42.247.00.000.000'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:43
centrale proxy[1748]: NOTICE: <script>: New reply on proxy - ID=«
abcd31f5-a9734654-1d07bf1 at 127.0.0.1» UA='A510 IP/42.076.00.000.000'



Thanks again

-- 
Stefano


On 16 July 2021 at 11:09:42, Marco Capetta (mcapetta at sipwise.com) wrote:

Hi Stefano,

I think to investigate the problem we need more information about the call
and more verbose logs.

Some suggestions to quickly fix the problem:
 - Disable the call deflection for that subscriber (call_deflection
preference)
 - Provide a more strict NCOS level in order to block all outgoing calls to
certain numbers or counties.

Regards
Marco


On 16/07/21 08:48, [ EXT ] Stefano Rogna Manassero di Costigliole wrote:

Hello all,

I need some help to sort this out: we have attacks mainly on Cisco SPAs
that seem to use some call redirection weakness changing caller ID:

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Redirect from UAC to
'«00377630547760»:«c.voceblu.it»' intercepted - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Callee is not local - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Call to SIP Peering - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Load gws matching calling part '«
sip:0691516096 at c.voceblu.it»' and called user '«00377630547760»' and called
part '«sip:00377630547760 at c.voceblu.it;transport=udp»' - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting acc source-leg for uuid
'«d0019f4a-285a-47ee-b7fd-46fcbdd68586»':
'«d0019f4a-285a-47ee-b7fd-46fcbdd68586|0122622461|c.voceblu.it|390122622461||2682|321|||<null>|cfb|213.204.31.10|1626364769.807718||||||||||||390122622461||||||8|»'
- R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Rewriting acc called party
'«00377630547760»' to '«377630547760»' - R=«
sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting acc destination-leg for
uuid '«0»':
'«0|||0|00377630547760|0|00377630547760|213.204.30.51|00377630547760|
c.voceblu.it|3||||||||||||377630547760|||»' - R=«
sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting
caller_cli_userprov/caller_domain_userprov '«0691516096»@«213.204.31.10»'
for upn - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting From to '<«
sip:0691516096 at 213.204.31.10»>' - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting
caller_cli_userprov/caller_domain_userprov '«0691516096»@«213.204.31.10»'
for upn - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting PAI to '<«
sip:0691516096 at 213.204.31.10»>' - R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Rewriting called party
'«00377630547760»' to '«377630547760»' - R=«
sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting P-Called-Party-ID '
<sip:«377630547760»@«213.204.30.51»> <sip:«377630547760»@«213.204.30.51»>'
- R=«sip:377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Setting 'sip:«213.204.30.51»:«5060»'
taken from D-URI as next hop after lb for PSTN call - R=«
sip:377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Appending P-D-URI '«
sip:127.0.0.1:5060;received=sip:213.204.30.51:5060%3blr%3btransport%3dudp»'
- R=«sip:377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Forcing request via B2BUA '«
sip:127.0.0.1:5080»' - R=«sip:377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Dropping local branch - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 17:59:29
centrale proxy[1748]: NOTICE: <script>: Request leaving server, M=INVITE
fs='«127.0.0.1»:«5062»' du='«127.0.0.1»:«5080»' - R=«
sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f059fe-46c55b62-12e232b0-1062088f at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Redirect from UAC to
'«00377630547760»:«c.voceblu.it»' intercepted - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Callee is not local - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Call to SIP Peering - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Load gws matching calling part '«
sip:0691516096 at c.voceblu.it»' and called user '«00377630547760»' and called
part '«sip:00377630547760 at c.voceblu.it;transport=udp»' - R=«
sip:00377630547760 at c.voceblu.it;transport=udp» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

/var/log/ngcp/kamailio-proxy.log-20210715-1626365821.gz:Jul 15 18:00:42
centrale proxy[1737]: NOTICE: <script>: Setting acc source-leg for uuid
'«d0019f4a-285a-47ee-b7fd-46fcbdd68586»':
'«d0019f4a-285a-47ee-b7fd-46fcbdd68586|0122622461|c.voceblu.it|390122622461||2682|321|||<null>|cfb|213.204.31.10|1626364842.837492||||||||||||390122622461||||||8|»'
- R=«sip:00377630547760 at 213.204.30.51» ID=«
0e15e0000ef5-60f05a47-2b9db9b2-140e3760-10620bdf at 127.0.0.1» UA='TELES-SBC'

Restricting allowed_clis does not seem to solve the problem

allowed_clis Allowed CLIs for outbound calls 390122622461

Any suggestion on how to block / solve the problem, please?

Thanks

Stefano



-- 
* Marco Capetta *
Head Of VoIP Development Team

Sipwise GmbH <http://www.sipwise.com> , Campus 21/Europaring F15
AT-2345 Brunn am Gebirge

Phone:  +43(0)1 301 2044 <+43130120444>
Email:  mcapetta at sipwise.com
Website:  www.sipwise.com

Particulars according Austrian Companies Code paragraph 14
"Sipwise GmbH" - Europaring F15 - 2345 Brunn am Gebirge
FN:305595f, Commercial Court Vienna, ATU64002206
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.sipwise.com/pipermail/spce-user_lists.sipwise.com/attachments/20210717/f0937030/attachment-0002.html>


More information about the Spce-user mailing list