Bionic
Occasional Visitor
Need help w/ Anveo Direct sip provider most secure setup using ASUS AC68U with Latest Merlin FW.
Per Anveo Direct, For SIP Signaling I need to allow their IP addresses to reach my IP PBX. Plus I also need to open ALL RTP ports that my IP PBX is using, to be able to receive RTP (Audio Stream) from underlying carriers. What is the most secure way to do this?
I currently have everything working by forwarding ports 5061, 5060, 5010, & 10000-20000 to the internal IP address of my IP PBX. But I know this is not the most secure way to do this... I have already noticed in my logs that the hackers are already attempting to register and make international calls...
I am using an ASUS Router with Merlin Firmware. I think if I do a custom iptable to only accept incoming traffic from Anveo Direct IP's through those ports, that would stop the hackers from reaching my IP PBX server?? If so what would be the correct syntax I should use for IPTables ? Or is there a better way for me to setup Anveo Direct with out having to do any port forwards? Anveo Direct uses direct media, with out RTP forwards will the carriers be able to connect to the stream directly?
Anveo Direct IP's
67.212.84.21,
176.9.39.206,
50.22.102.242,
50.22.101.14,
72.9.149.25,
Per Anveo Direct, For SIP Signaling I need to allow their IP addresses to reach my IP PBX. Plus I also need to open ALL RTP ports that my IP PBX is using, to be able to receive RTP (Audio Stream) from underlying carriers. What is the most secure way to do this?
I currently have everything working by forwarding ports 5061, 5060, 5010, & 10000-20000 to the internal IP address of my IP PBX. But I know this is not the most secure way to do this... I have already noticed in my logs that the hackers are already attempting to register and make international calls...
I am using an ASUS Router with Merlin Firmware. I think if I do a custom iptable to only accept incoming traffic from Anveo Direct IP's through those ports, that would stop the hackers from reaching my IP PBX server?? If so what would be the correct syntax I should use for IPTables ? Or is there a better way for me to setup Anveo Direct with out having to do any port forwards? Anveo Direct uses direct media, with out RTP forwards will the carriers be able to connect to the stream directly?
Anveo Direct IP's
67.212.84.21,
176.9.39.206,
50.22.102.242,
50.22.101.14,
72.9.149.25,