300-070 · Question #161
Hackers are sending calls through a gateway router that is running SIP. The engineer blocks all SIP messages to the router except from their SIP server, which has an IP address of 208.177.10.1. The…
The correct answer is B. voice service voip. The correct solution uses 'voice service voip' with an 'ip address trusted list' to whitelist only the authorized SIP sources. Option B is the command set that correctly adds both the SIP server (208.177.10.1) and the Cisco Expressway server (10.1.10.110) to the trusted list…
Question
Hackers are sending calls through a gateway router that is running SIP. The engineer blocks all SIP messages to the router except from their SIP server, which has an IP address of 208.177.10.1. The customer also must connect via SIP to their Cisco Expressway server with an IP address of 10.1.10.110. Which series of commands secures the router from the hackers?
Options
- Avoice service voip
- Bvoice service voip
- Cvoice service voip
- Dvoice service voip
How the community answered
(30 responses)- A30% (9)
- B47% (14)
- C7% (2)
- D17% (5)
Explanation
The correct solution uses 'voice service voip' with an 'ip address trusted list' to whitelist only the authorized SIP sources. Option B is the command set that correctly adds both the SIP server (208.177.10.1) and the Cisco Expressway server (10.1.10.110) to the trusted list under 'voice service voip'. Cisco IOS SIP gateways will reject SIP INVITE and REGISTER messages from any IP not on the trusted list, effectively blocking the hackers while allowing legitimate traffic. The other options either use incorrect IP addresses, missing entries, or wrong syntax.
Topics
Community Discussion
No community discussion yet for this question.