Re: [VoiceOps] VoIP Provider DDoSes

2021-10-08 Thread Alex Balashov
I would agree, but modify this advice to read: “TCP or TLS to the edge for end-users, then step down to UDP with big MTUs inside the service provider core.” — Sent from mobile, with due apologies for brevity and errors. > On Oct 8, 2021, at 8:25 AM, Tim Bray via VoiceOps > wrote: > >  >

Re: [VoiceOps] VoIP Provider DDoSes

2021-10-08 Thread Tim Bray via VoiceOps
UDP fragments have been a problem for years. mitigations historically have been to turn off spare codecs.  On snom phones, turn off fancy features. Tbh, the only really modern mitigation is just to use SIP over TLS and taking UDP out of the mix for everything except media. Tim On