
Oracle SBC Security Guide
NN 6300 724k CAM 16G memory – copper single GigE
access-control-trust-level
untrusted-signal-threshold
access-control-trust-level
untrusted-signal-threshold
Observations/Limitations
The settings outlined in this appendix are beneficial when facing malicious or non-malicious flood
attacks, such as a REGISTER avalanche following a network outage. By limiting the amount of untrusted
traffic to the SBC, the registration rate allowed will be throttled and the SBC will not be overrun by the
high rate of registrations. However, there is an opportunity cost between the level of protection against a
DDoS flood attack and the convergence time for this type of avalanche condition. For example, raising
the percentage of untrusted bandwidth allowed will inevitably allow more untrusted traffic to traverse the
SBC, and minimize the convergence time. The opportunity cost here is higher CPU usage during the
flood, a result of higher demand on the processor due to the increased level of registrations it’s required to
process.
Additionally, when set as an option in the sip-configuration, reg-overload-protect requires the SBC
temporarily promote a registering endpoint upon receipt of a 401/407 response from the “real” registrar.
This temporary promotion is in advance of the real and final promotion, which takes place following the
200 OK response to a REGISTER request containing authentication credentials. During a registration
Komentarze do niniejszej Instrukcji