Koozali.org: home of the SME Server

Obsolete Releases => SME 7.x Contribs => Topic started by: portedaix on July 27, 2010, 11:03:37 PM

Title: Firewall rule with sail
Post by: portedaix on July 27, 2010, 11:03:37 PM
Hello,

My sip provider is ovh, france. I have this line "chan_sip.c:7289 determine_firstline_parts: Bad request protocol Packet" coming up in asterisk cli. I saw at least another adsl box sip line provider creating this message (freephonie france). It seems to be harmless to asterisk, just a package which should be droped silently. But my log file is getting quite fat ! And cli reading is not nice. asterisk-1.6 did not display it. But it is not compatible with sail.

The only fix I found is to enter the rule
                'iptables -I INPUT -p udp --src 123.123.123.123 --dport 5060 -m string --algo bm --string "Cirpack KeepAlive" -j DROP Packet'
But with sme and its templates, I do not know how to fix it. Any idea not to see this message again ?

Thanks for any hint.
Olivier
Title: Re: Firewall rule with sail
Post by: janet on July 28, 2010, 01:06:51 AM
portedaix

Add your rule to a custom template for masq.
See
http://wiki.contribs.org/Template_Tutorial
Title: Re: Firewall rule with sail
Post by: CharlieBrady on August 02, 2010, 08:08:46 PM
The only fix I found is to enter the rule
                'iptables -I INPUT -p udp --src 123.123.123.123 --dport 5060 -m string --algo bm --string "Cirpack KeepAlive" -j DROP Packet'
But with sme and its templates, I do not know how to fix it.

I do not think SME includes the string match iptables module, so I don't think templates will be sufficient.
Title: Re: Firewall rule with sail
Post by: CharlieBrady on August 02, 2010, 08:12:46 PM
A patch is available for Asterix.

http://lists.digium.com/pipermail/asterisk-dev/2006-May/021033.html

If the only problem is that your log file is becoming large, then just add rules to rotate it more often. Or just ignore it if your disk is large enough.