cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1432
Views
5
Helpful
8
Replies

Router randomly dials numbers

paolonova
Level 1
Level 1

Hi all,

I have a Cisco 2901 with CME 15.4. I have a couple of 7821 and an analogue phone connected to it. As soon as I turn on

debug voice dialpeer

I have a verbose output activity, apparenlty numbers called randomly. All my phones are on-hook though. Just an example:

Calling Number=1001, Called Number=800972595264989, Voice-Interface=0x0,
Timeout=TRUE, Peer Encap Type=ENCAP_VOIP, Peer Search Type=PEER_TYPE_VOICE,
Peer Info Type=DIALPEER_INFO_SPEECH
*Nov 4 12:01:33.622 GMT: //-1/A065BB7D83B7/DPM/dpAssociateIncomingPeerCore:
Result=NO_MATCH(-1) After All Match Rules Attempt
*Nov 4 12:01:33.622 GMT: //-1/A065BB7D83B7/DPM/dpMatchSafModulePlugin:
dialstring=NULL, saf_enabled=0, saf_dndb_lookup=0, dp_result=-1

Calling Number=.00972592821380, Called Number=.00972592821380, Peer Info Type=DIALPEER_INFO_SPEECH
*Nov 4 12:02:44.079 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:
Match Rule=DP_MATCH_DEST; Called Number=.00972592821380
*Nov 4 12:02:44.079 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:
No Outgoing Dial-peer Is Matched; Result=NO_MATCH(-1)

Calling Number=+972592880428, Called Number=+972592880428, Peer Info Type=DIALPEER_INFO_SPEECH
*Nov 4 12:03:27.231 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:
Match Rule=DP_MATCH_DEST; Called Number=+972592880428
*Nov 4 12:03:27.231 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:

Please find in attach the output of show dialpeer voice and port summary.

Thank you

1 Accepted Solution

Accepted Solutions

Seems like Toll Fraud attempts to your GW. I see that call was blocked by TOLLFRAUD_APP in IOS and you do not have to worry :)

*Nov  5 08:43:12.547 GMT: //-1/xxxxxxxxxxxx/CCAPI/cc_setupind_match_search:
   Try with the demoted called number 900442476980898
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallSetContext:
   Context=0x21021E2C
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/cc_process_call_setup_ind:
   >>>>CCAPI handed cid 2042 with tag 0 to app "_ManagedAppProcess_TOLLFRAUD_APP"
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
   Cause Value=21, Tag=0x0, Call Entry(Previous Disconnect Cause=0, Disconnect Cause=0)
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
   Cause Value=21, Call Entry(Responsed=TRUE, Cause Value=21)

Thanks,

Kasi

View solution in original post

8 Replies 8

devils_advocate
Level 7
Level 7

Can you provide the full config?

Have you got any IP SLA settings configured?

Hi and thank you for your reply

No, I don't have any IP SLA setting configured.

Here's the running conf.

I do not see anything unusual with the config.

Execute "show ip address trusted list" and ensure it is Admin/Operationally UP and also check only the known IPs are in the trust list.

If you still find those calls, provide us the "debug voice ccapi inout" output.

Thanks,

Kasi

Hi Kasiraman and thank you 

Here's the output of #show ip address trusted list


IP Address Trusted Authentication
Administration State: UP
Operation State: UP

IP Address Trusted Call Block Cause: call-reject (21)

VoIP Dial-peer IPv4 and IPv6 Session Targets:
Peer Tag Oper State Session Target
-------- ---------- --------------
80980 UP ipv4:10.100.159.65

IP Address Trusted List:

Please find in attach the debug voice ccapi inout

Seems like Toll Fraud attempts to your GW. I see that call was blocked by TOLLFRAUD_APP in IOS and you do not have to worry :)

*Nov  5 08:43:12.547 GMT: //-1/xxxxxxxxxxxx/CCAPI/cc_setupind_match_search:
   Try with the demoted called number 900442476980898
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallSetContext:
   Context=0x21021E2C
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/cc_process_call_setup_ind:
   >>>>CCAPI handed cid 2042 with tag 0 to app "_ManagedAppProcess_TOLLFRAUD_APP"
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
   Cause Value=21, Tag=0x0, Call Entry(Previous Disconnect Cause=0, Disconnect Cause=0)
*Nov  5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
   Cause Value=21, Call Entry(Responsed=TRUE, Cause Value=21)

Thanks,

Kasi

Ok thank you very much, although this doesn't explain why I have such a lot of random calls trying to get out. 

I would like to understand why they are generated and block them before toll fraud, possibly.

I have an average of a new random call every 10/20seconds.

This is very much possible that the Voice Gateway which are facing internet get these kind of Toll Fraud calls and the built in Toll Fraud app is the best way to block those calls and other methods we can use are ACL which will drop those calls as soon those enter the Router which is really old method and they are not suggested these days.

Please take a look at the below URL to know about the Toll-Fraud Prevention Feature in IOS Release 15.1(2)T and later.

http://www.cisco.com/c/en/us/support/docs/voice/call-routing-dial-plans/112083-tollfraud-ios.html

Thanks,

Kasi

Ok, thank you very much again for your help.