11-04-2015 04:34 AM - edited 03-17-2019 04:48 AM
Hi all,
I have a Cisco 2901 with CME 15.4. I have a couple of 7821 and an analogue phone connected to it. As soon as I turn on
debug voice dialpeer
I have a verbose output activity, apparenlty numbers called randomly. All my phones are on-hook though. Just an example:
Calling Number=1001, Called Number=800972595264989, Voice-Interface=0x0,
Timeout=TRUE, Peer Encap Type=ENCAP_VOIP, Peer Search Type=PEER_TYPE_VOICE,
Peer Info Type=DIALPEER_INFO_SPEECH
*Nov 4 12:01:33.622 GMT: //-1/A065BB7D83B7/DPM/dpAssociateIncomingPeerCore:
Result=NO_MATCH(-1) After All Match Rules Attempt
*Nov 4 12:01:33.622 GMT: //-1/A065BB7D83B7/DPM/dpMatchSafModulePlugin:
dialstring=NULL, saf_enabled=0, saf_dndb_lookup=0, dp_result=-1
Calling Number=.00972592821380, Called Number=.00972592821380, Peer Info Type=DIALPEER_INFO_SPEECH
*Nov 4 12:02:44.079 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:
Match Rule=DP_MATCH_DEST; Called Number=.00972592821380
*Nov 4 12:02:44.079 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:
No Outgoing Dial-peer Is Matched; Result=NO_MATCH(-1)
Calling Number=+972592880428, Called Number=+972592880428, Peer Info Type=DIALPEER_INFO_SPEECH
*Nov 4 12:03:27.231 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:
Match Rule=DP_MATCH_DEST; Called Number=+972592880428
*Nov 4 12:03:27.231 GMT: //-1/xxxxxxxxxxxx/DPM/dpMatchPeersCore:
Please find in attach the output of show dialpeer voice and port summary.
Thank you
Solved! Go to Solution.
11-05-2015 01:21 AM
Seems like Toll Fraud attempts to your GW. I see that call was blocked by TOLLFRAUD_APP in IOS and you do not have to worry :)
*Nov 5 08:43:12.547 GMT: //-1/xxxxxxxxxxxx/CCAPI/cc_setupind_match_search:
Try with the demoted called number 900442476980898
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallSetContext:
Context=0x21021E2C
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/cc_process_call_setup_ind:
>>>>CCAPI handed cid 2042 with tag 0 to app "_ManagedAppProcess_TOLLFRAUD_APP"
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
Cause Value=21, Tag=0x0, Call Entry(Previous Disconnect Cause=0, Disconnect Cause=0)
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
Cause Value=21, Call Entry(Responsed=TRUE, Cause Value=21)
Thanks,
Kasi
11-04-2015 06:23 AM
Can you provide the full config?
Have you got any IP SLA settings configured?
11-04-2015 07:21 AM
11-04-2015 07:45 AM
I do not see anything unusual with the config.
Execute "show ip address trusted list" and ensure it is Admin/Operationally UP and also check only the known IPs are in the trust list.
If you still find those calls, provide us the "debug voice ccapi inout" output.
Thanks,
Kasi
11-05-2015 12:49 AM
Hi Kasiraman and thank you
Here's the output of #show ip address trusted list
IP Address Trusted Authentication
Administration State: UP
Operation State: UP
IP Address Trusted Call Block Cause: call-reject (21)
VoIP Dial-peer IPv4 and IPv6 Session Targets:
Peer Tag Oper State Session Target
-------- ---------- --------------
80980 UP ipv4:10.100.159.65
IP Address Trusted List:
Please find in attach the debug voice ccapi inout
11-05-2015 01:21 AM
Seems like Toll Fraud attempts to your GW. I see that call was blocked by TOLLFRAUD_APP in IOS and you do not have to worry :)
*Nov 5 08:43:12.547 GMT: //-1/xxxxxxxxxxxx/CCAPI/cc_setupind_match_search:
Try with the demoted called number 900442476980898
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallSetContext:
Context=0x21021E2C
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/cc_process_call_setup_ind:
>>>>CCAPI handed cid 2042 with tag 0 to app "_ManagedAppProcess_TOLLFRAUD_APP"
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
Cause Value=21, Tag=0x0, Call Entry(Previous Disconnect Cause=0, Disconnect Cause=0)
*Nov 5 08:43:12.547 GMT: //2042/1536D1D3A2B3/CCAPI/ccCallDisconnect:
Cause Value=21, Call Entry(Responsed=TRUE, Cause Value=21)
Thanks,
Kasi
11-05-2015 02:10 AM
Ok thank you very much, although this doesn't explain why I have such a lot of random calls trying to get out.
I would like to understand why they are generated and block them before toll fraud, possibly.
I have an average of a new random call every 10/20seconds.
11-05-2015 02:36 AM
This is very much possible that the Voice Gateway which are facing internet get these kind of Toll Fraud calls and the built in Toll Fraud app is the best way to block those calls and other methods we can use are ACL which will drop those calls as soon those enter the Router which is really old method and they are not suggested these days.
Please take a look at the below URL to know about the Toll-Fraud Prevention Feature in IOS Release 15.1(2)T and later.
http://www.cisco.com/c/en/us/support/docs/voice/call-routing-dial-plans/112083-tollfraud-ios.html
Thanks,
Kasi
11-05-2015 03:32 AM
Ok, thank you very much again for your help.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide