05-15-2020 06:44 AM
Hello,
I have a remote site with my VG connected directly to the Internet, I would like to know what will be the best practices in security that are recommended?
Thanks.
05-15-2020 06:53 AM
if the security is concern, moving the kit behind any FW is good option.
05-15-2020 07:10 AM
I know that would be the best practices, but this is a remote site with few phones and the customer will not put a firewall.
thanks.
05-15-2020 07:03 AM
What Feature Set does you gateway have? Ideally you'd configure as a firewall permitting access only to your ITSP. If you don't have the security licence you may be able to get away with straight ACLs permitting only your ITSP's proxy and only the destinations and protocols needed.
05-15-2020 07:22 AM
Hello,
So the best practices will just allow the ports between the CUCM and the VG?
Will this doc help?
thanks.
05-15-2020 07:57 AM
Your concern should be on the Internet side of the gateway. You do not want folk on the Internet accessing your gateway and making phone calls at your expense. Lock down that side so that nothing except your service provider can access your gateway, and even then try and limit the ports protocols and destinations it can reach. I also like to use COR so that the service provider dial peers can't "see" anything except the CUCM facing dial peers.
05-15-2020 08:33 AM
Can you provide an example about this security configuration?
thanks.
05-15-2020 09:18 AM
I'll try and look something out, but I think most of the gateways I look after are either dual purpose VG and Internet access, in which case the configuration is more complex, or are placed inside a separate firewall. If I can't find one I can draught out the outline which you can then tweak for your exact scenario.
If you want an emergency quick protection then stick an extended access list on the Internet interface permitting just the two host addresses, where x.x.x.x is your gateway IP and y.y.y.y is your service provider
ip access-list extended SECURE permit ip host y.y.y.y host x.x.x.x
That's better than nothing.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide