VoIP Mechanic

Asterisk™ Security primer

"Helping you make your
Asterisk PBX more secure."

Securing SIP Asterisk installations effectively is a "must" today and by taking a few easy steps you can go a long way towards a more secure phone system.  There are a few easy preventative steps that you can take which will make malicious intruders have a much harder time in abusing your SIP phone system.  Unfortunately, there are some easily obtainable SIP scanners widely available that make it much easier today for hacking into a ]system.  It was not long ago when these attempts were fairly prevalent and some systems were compromised allowing culprits to make thousands of toll calls at the owners expense.  Since that time awareness of potential SIP  vulnerabilities has increased and many installations of Asterisk have been "hardened", but many others may not have been.   For those we recommend the following easy steps that will make any attempts to exploit an easy target much more difficult, and in most cases not worth the effort.

Security on an Asterisk PBX is important.  Take a few steps.

 

 

 

5 Steps to a more secure Asterisk

One more good security step.

Malicious intruders on VoIP systems typically try to make tool calls and the most expensive and costly are International calls. 

There are many more other security measures that can be taken on a network which will further secure access, including using non-standard ports, closing down your firewall except for specific ports needed for your voice and other applications.  Creating VLANs for voice is another good practice which segregates the voice side of the network, limiting access.  The above five suggestions are easy, necessary and can go a long way in prevented unauthorized intruders in using your system to make toll calls that end up on your account.  This happened in Australia where an unsuspecting business go hit with thousands of dollars worth of International calls over the short period of  2 days.  Targeting unprotected systems thieves hack into the system and exploit call-forwarding to sends calls out racking up toll charges.

Keep your Asterisk server lean.

Limit the services on your Linux operating system to only the essentials.  Turn off those services which are not needed.  You will also want to limit the what you install on the box.  It should only be Linux and Asterisk.  Consider: