RedMax EXtreme EX-LRT Instrukcja Naprawy Strona 59

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 58
Oracle SBC Security Guide
NN 6300 724k CAM 16G memory copper single GigE
Platform
NN 6300
CAM
724K
Memory
16G
Software Release
7.1.2
Configuration Model
PBRB
SSNHTN
SNB
media-manager
max-signaling-bandwidth
2500000
max-untrusted-signaling
1
1
1
min-untrusted-signaling
1
1
1
tolerance-window
30
realm-config (peer)
access-control-trust-level
low
average-rate-limit
0
invalid-signal-threshold
1
maximum-signal-threshold
4000
untrusted-signal-threshold
1
realm-config (core)
access-control-trust-level
high
average-rate-limit
0
invalid-signal-threshold
0
maximum-signal-threshold
0
untrusted-signal-threshold
0
Observations/Limitations
The settings outlined in this appendix are beneficial when facing malicious or non-malicious flood
attacks, such as a REGISTER avalanche following a network outage. By limiting the amount of untrusted
traffic to the SBC, the registration rate allowed will be throttled and the SBC will not be overrun by the
high rate of registrations. However, there is an opportunity cost between the level of protection against a
DDoS flood attack and the convergence time for this type of avalanche condition. For example, raising
the percentage of untrusted bandwidth allowed will inevitably allow more untrusted traffic to traverse the
SBC, and minimize the convergence time. The opportunity cost here is higher CPU usage during the
flood, a result of higher demand on the processor due to the increased level of registrations it’s required to
process.
Additionally, when set as an option in the sip-configuration, reg-overload-protect requires the SBC
temporarily promote a registering endpoint upon receipt of a 401/407 response from the “real” registrar.
This temporary promotion is in advance of the real and final promotion, which takes place following the
200 OK response to a REGISTER request containing authentication credentials. During a registration
Przeglądanie stron 58
1 2 ... 54 55 56 57 58 59 60 61 62 63 64 ... 141 142

Komentarze do niniejszej Instrukcji

Brak uwag