zur Firewall: Ich habe zum Test SIP von außen per Portforwarding durchgeleitet. Das werde ich nun wieder ausschalten. Aber evtl. bringt uns das weiter - ganz am Ende dieses Threads kommt ne anfrage von "außen".
Zum Mitschnitt:
Mein Filter ATM:
!(ip.addr == 192.168.1.208) and sip
Damit blende ich alle internen SIP Geräte aus da diese im Moment noch über eine Fritzbox angebunden sind.
Nach außen Verbinde ich zu Sipgate als Backup und zu Pfalzconnect als "Hauptleitungen".
Damit ich nun mal weis was davon Sipgate ist hab ich mir deren IPv4 Range angeschaut und laut deren Website sind es folgende:
- 217.10.64.0/20
- 217.116.112.0/20
- 212.9.32.0/19
Damit erweitert sehe ich wie es aussehen soll:
!(ip.addr == 192.168.1.208) and sip and (ip.addr == 217.10.64.0/20 || ip.addr == 217.116.112.0/20 || ip.addr == 212.9.32.0/19)
Code:
No. Time Source Destination Protocol Length Info
111 23.289595 192.168.1.254 217.10.79.9 SIP 478 Request: OPTIONS sip:[email protected] |
112 23.295858 217.10.79.9 192.168.1.254 SIP 419 Status: 200 OK |
158 44.402211 192.168.1.254 217.10.79.9 SIP 613 Request: REGISTER sip:sipgate.de:5060 (1 binding) |
159 44.410871 217.10.79.9 192.168.1.254 SIP 517 Status: 401 Unauthorized |
160 44.412295 192.168.1.254 217.10.79.9 SIP 791 Request: REGISTER sip:sipgate.de:5060 (1 binding) |
161 44.421936 217.10.79.9 192.168.1.254 SIP 523 Status: 200 OK (1 binding) |
284 83.290816 192.168.1.254 217.10.79.9 SIP 478 Request: OPTIONS sip:[email protected] |
285 83.296972 217.10.79.9 192.168.1.254 SIP 419 Status: 200 OK |
457 143.291536 192.168.1.254 217.10.79.9 SIP 478 Request: OPTIONS sip:[email protected] |
458 143.297838 217.10.79.9 192.168.1.254 SIP 419 Status: 200 OK |
502 154.423524 192.168.1.254 217.10.79.9 SIP 613 Request: REGISTER sip:sipgate.de:5060 (1 binding) |
503 154.432005 217.10.79.9 192.168.1.254 SIP 517 Status: 401 Unauthorized |
504 154.433187 192.168.1.254 217.10.79.9 SIP 791 Request: REGISTER sip:sipgate.de:5060 (1 binding) |
505 154.441708 217.10.79.9 192.168.1.254 SIP 523 Status: 200 OK (1 binding) |
656 203.290989 192.168.1.254 217.10.79.9 SIP 478 Request: OPTIONS sip:[email protected] |
657 203.297157 217.10.79.9 192.168.1.254 SIP 419 Status: 200 OK |
846 263.306978 192.168.1.254 217.10.79.9 SIP 478 Request: OPTIONS sip:[email protected] |
847 263.313288 217.10.79.9 192.168.1.254 SIP 419 Status: 200 OK |
Bereinigt um meine SIP ID.
Hier kommt regelmäßig ein "Status: 401 Unauthorized" - das sollte doch so auch nicht sein, oder?
Mit einem Ausrufezeichen mehr sehe ich nun Pfalzconnect:
!(ip.addr == 192.168.1.208) and sip and !(ip.addr == 217.10.64.0/20 || ip.addr == 217.116.112.0/20 || ip.addr == 212.9.32.0/19)
Code:
No. Time Source Destination Protocol Length Info
519 160.758407 192.168.1.254 77.244.109.179 SIP 496 Request: OPTIONS sip:sip.pfalzconnect.de |
520 160.764195 77.244.109.179 192.168.1.254 SIP 574 Status: 503 Not Implemented - Fake Return Code |
538 172.167273 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
539 172.173292 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
599 201.163270 192.168.1.254 77.244.109.179 SIP 530 Request: OPTIONS sip:[email protected]:5060 |
600 201.168933 77.244.109.179 192.168.1.254 SIP 589 Status: 503 Not Implemented - Fake Return Code |
660 203.804769 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
661 203.810664 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
670 206.898385 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
671 206.904196 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
672 207.012334 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
673 207.018132 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
677 209.258800 192.168.1.254 77.244.109.179 SIP 530 Request: OPTIONS sip:[email protected]:5060 |
678 209.264880 77.244.109.179 192.168.1.254 SIP 589 Status: 503 Not Implemented - Fake Return Code |
685 211.386520 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
686 211.392605 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
705 220.773576 192.168.1.254 77.244.109.179 SIP 496 Request: OPTIONS sip:sip.pfalzconnect.de |
706 220.779527 77.244.109.179 192.168.1.254 SIP 574 Status: 503 Not Implemented - Fake Return Code |
715 223.428466 192.168.1.254 91.212.38.226 ICMP 484 Destination unreachable (Port unreachable)
728 232.168473 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
729 232.174547 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
794 261.162998 192.168.1.254 77.244.109.179 SIP 530 Request: OPTIONS sip:[email protected]:5060 |
795 261.169295 77.244.109.179 192.168.1.254 SIP 589 Status: 503 Not Implemented - Fake Return Code |
848 263.805718 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
849 263.811897 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
856 266.899774 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
857 266.905452 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
858 267.013921 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
859 267.019715 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
864 269.255889 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
865 269.261583 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
869 271.385406 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
870 271.391466 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
899 280.758710 192.168.1.254 77.244.109.179 SIP 496 Request: OPTIONS sip:sip.pfalzconnect.de |
900 280.764793 77.244.109.179 192.168.1.254 SIP 574 Status: 503 Not Implemented - Fake Return Code |
925 292.168428 192.168.1.254 77.244.109.179 SIP 528 Request: OPTIONS sip:[email protected]:5060 |
926 292.174678 77.244.109.179 192.168.1.254 SIP 587 Status: 503 Not Implemented - Fake Return Code |
978 321.164753 192.168.1.254 77.244.109.179 SIP 530 Request: OPTIONS sip:[email protected]:5060 |
979 321.171077 77.244.109.179 192.168.1.254 SIP 589 Status: 503 Not Implemented - Fake Return Code |
1033 323.805301 192.168.1.254 77.244.109.179 SIP 528 Request: OPTIONS sip:[email protected]:5060 |
1034 323.811317 77.244.109.179 192.168.1.254 SIP 587 Status: 503 Not Implemented - Fake Return Code |
1038 326.617452 192.168.1.254 77.244.109.179 SIP 654 Request: REGISTER sip:sip.pfalzconnect.de:5060 (1 binding) |
1039 326.618112 192.168.1.254 77.244.109.179 SIP 654 Request: REGISTER sip:sip.pfalzconnect.de:5060 (1 binding) |
1040 326.623252 77.244.109.179 192.168.1.254 SIP 624 Status: 401 Unauthorized |
1041 326.623253 77.244.109.179 192.168.1.254 SIP 624 Status: 401 Unauthorized |
1042 326.624426 192.168.1.254 77.244.109.179 SIP 895 Request: REGISTER sip:sip.pfalzconnect.de:5060 (1 binding) |
1043 326.625461 192.168.1.254 77.244.109.179 SIP 895 Request: REGISTER sip:sip.pfalzconnect.de:5060 (1 binding) |
1044 326.630399 77.244.109.179 192.168.1.254 SIP 440 Status: 100 Trying |
1045 326.631116 77.244.109.179 192.168.1.254 SIP 440 Status: 100 Trying |
1046 326.637903 77.244.109.179 192.168.1.254 SIP 602 Status: 200 OK (1 binding) |
1047 326.637905 77.244.109.179 192.168.1.254 SIP 602 Status: 200 OK (1 binding) |
1048 326.899444 192.168.1.254 77.244.109.179 SIP 527 Request: OPTIONS sip:[email protected]:5060 |
1049 326.905601 77.244.109.179 192.168.1.254 SIP 586 Status: 503 Not Implemented - Fake Return Code |
1050 327.012849 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
1051 327.018563 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
1055 329.255914 192.168.1.254 77.244.109.179 SIP 530 Request: OPTIONS sip:[email protected]:5060 |
1056 329.261822 77.244.109.179 192.168.1.254 SIP 589 Status: 503 Not Implemented - Fake Return Code |
1057 329.593503 192.168.1.254 77.244.109.179 SIP 654 Request: REGISTER sip:sip.pfalzconnect.de:5060 (1 binding) |
1058 329.599188 77.244.109.179 192.168.1.254 SIP 624 Status: 401 Unauthorized |
1059 329.600820 192.168.1.254 77.244.109.179 SIP 895 Request: REGISTER sip:sip.pfalzconnect.de:5060 (1 binding) |
1060 329.606718 77.244.109.179 192.168.1.254 SIP 440 Status: 100 Trying |
1061 329.616278 77.244.109.179 192.168.1.254 SIP 602 Status: 200 OK (1 binding) |
1065 331.386906 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
1066 331.393167 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
1084 340.773974 192.168.1.254 77.244.109.179 SIP 496 Request: OPTIONS sip:sip.pfalzconnect.de |
1085 340.780032 77.244.109.179 192.168.1.254 SIP 574 Status: 503 Not Implemented - Fake Return Code |
1101 352.168719 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
1102 352.174995 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
1178 381.165350 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
1179 381.171222 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
1240 383.805934 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
1241 383.811944 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
1251 386.900156 192.168.1.254 77.244.109.179 SIP 528 Request: OPTIONS sip:[email protected]:5060 |
1252 386.905791 77.244.109.179 192.168.1.254 SIP 587 Status: 503 Not Implemented - Fake Return Code |
1253 387.013918 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
1254 387.019673 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
1259 389.256563 192.168.1.254 77.244.109.179 SIP 530 Request: OPTIONS sip:[email protected]:5060 |
1260 389.262485 77.244.109.179 192.168.1.254 SIP 589 Status: 503 Not Implemented - Fake Return Code |
1268 391.387911 192.168.1.254 77.244.109.179 SIP 529 Request: OPTIONS sip:[email protected]:5060 |
1269 391.393917 77.244.109.179 192.168.1.254 SIP 588 Status: 503 Not Implemented - Fake Return Code |
1286 400.760744 192.168.1.254 77.244.109.179 SIP 496 Request: OPTIONS sip:sip.pfalzconnect.de |
1287 400.766991 77.244.109.179 192.168.1.254 SIP 574 Status: 503 Not Implemented - Fake Return Code |
1328 412.168800 192.168.1.254 77.244.109.179 SIP 527 Request: OPTIONS sip:[email protected]:5060 |
1329 412.178066 77.244.109.179 192.168.1.254 SIP 586 Status: 503 Not Implemented - Fake Return Code |
1382 440.552120 192.168.1.254 51.89.99.24 ICMP 475 Destination unreachable (Port unreachable)
Hier etwas mehr Codeausschnitt da es doch zu vielen Fehlermeldungen kommt.
Etwas weiter unten im Protokoll gibts noch eine andere Meldung:
Code:
No. Time Source Destination Protocol Length Info
56471 14473.226075 77.247.110.23 192.168.1.254 SIP 591 Request: REGISTER sip:externalIP:5061 (1 binding) |
56472 14473.227254 192.168.1.254 77.247.110.23 SIP 449 Status: 403 Forbidden |
56478 14474.782158 77.247.110.23 192.168.1.254 SIP 591 Request: REGISTER sip:externalIP:5061 (1 binding) |
56479 14474.783668 192.168.1.254 77.247.110.23 SIP 449 Status: 403 Forbidden |
Das schaut für mich so aus als ob der pfalzconnect server ein register anfragt?!
Auch ist die 77.247.110.23 eine andere IP, vorher war es die 77.244.109.179 - Vom Range her denke ich die IPs hängen zusammen. Auch hier habe ich die "private" IP ausgegraut und "externalIP" hingeschrieben.
Ich hoffe damit kommen wir ein Stück weiter.
Vielen Dank schonmal,
Gruß Raphael
Edit:
Wireshark hat ja tolle Analysetools...
Vllt hilft auch das:
Hier noch die Statistik von 7h logs:
SIP Responses:
3297x 503 Service Unavailable Count - davon 4 Resent
15x 489 Bad Event
13x 481 Call/Transaction Does Not Exist
3x 423 Interval Too Brief
46x 404 Not Found
4067x 403 Forbidden - davon 3 Resent
767x 401 Unauthorized - davon 2 Resent
5757x 200 OK - davon 10 Resent
166x 100 Trying
SIP Requests:
425x SUBSCRIBE
5979x REGISTER - davon 725 Resent
14133x OPTIONS - davon 5236 Resent
290x NOTIFY - davon 34 Resent
4x INVITE