Blacklist IP addresses

The IP address whitelist/blacklist can be used to blacklist ranges of IP addresses based on the P-Source-Device header in the SIP INVITE. To whitelist/blacklist by IP address, the appropriate header must be present in the SIP INVITE to communicate the information to ClearIP.

P-Source-Device Header

Here is an example SIP Invite with a P-Source-Device header.

INVITE sip:+221775477743@sip.clearip.com:5060 SIP/2.0
Via: SIP/2.0/TCP 185.163.212.72:5070;branch=z9hG4bK+4890494bbf3238da4f07e773ff377d8c1+sip+2+ba8abc2f
From:  <sip:+33169483508@185.163.212.72:5070>;tag=185.163.212.72+2+bc397a11+1ffa86f6
To:  <sip:+221775477743@sip.clearip.com>
CSeq: 382160099 INVITE
Content-Length: 199
Contact:  <sip:7fd46d388b895ba2fe34875e960aa85c@185.163.212.72:5070;transport=tcp>;isup-oli=00
Content-Type: application/sdp
Call-ID: 0gQAAC8WAAACBAAALxYAAO5ptl+NYj9sCQ/d5Bc5O2vxee68hTzhE/HdZbesYrk2@185.163.212.72
Allow: INVITE,ACK,CANCEL,BYE,OPTIONS
Max-Forwards: 66
P-Asserted-Identity: <sip:+33169483508@185.163.212.72>
P-Source-Device: 104.248.129.175
Accept: application/sdp

v=0
o=- 83620636790542 83620636790542 IN IP4 185.163.212.72
s=-
c=IN IP4 185.163.212.72
t=0 0
m=audio 51040 RTP/AVP 8 18 101
a=rtpmap:101 telephone-event/8000
a=fmtp:18 annexb=no
a=ptime:20

If the SIP Invite contains a P-Source-Device header, then in the SIP Messages page, then the source IP address is populated in the P Source Device column. SIP Message P Source Device

Protect ClearIP Proxy from unknown devices

ClearIP users who use the ClearIP Proxy should set up a firewall to protect the host server running the ClearIP Proxy. However, ClearIP can also perform the same function using the IP Address Whitelist/Blacklist. ClearIP should receive calls through the ClearIP Proxy from familiar devices such as the telephone service provider’s softswitches or SBC’s and external provider devices.

ClearIP Proxy Diagram

Here, the user has blacklisted calls from all devices except their softswitch and devices belonging to their providers. For the calls that are received by familiar devices, the rest of the whitelist/blacklist policies such as Blacklisted Calling Numbers still apply.

IP Address Whitelist/Blacklist