; --------------------------------------------------------------------------- ; Hold Slayer lab — PJSIP configuration ; --------------------------------------------------------------------------- ; SECURITY: this endpoint answers calls. Asterisk's stock examples allow ; anonymous inbound, which is a well-known toll-fraud target. This config ; refuses it: every call must authenticate as the `hold-slayer` endpoint. ; ; There is no PSTN behind this Asterisk — an unauthorised call reaches only ; the lab dialplan and costs nothing. The lock-down is defence in depth and ; so this config is never copied somewhere it would matter. ; --------------------------------------------------------------------------- [global] type = global ; Do not fall through to an `anonymous` endpoint for unmatched calls. ; This is the single most important line in the file. unidentified_request_count = 5 unidentified_request_period = 5 unidentified_request_prune_interval = 30 [transport-udp] type = transport protocol = udp bind = 0.0.0.0:{{ asterisk_sip_port }} ; The address Asterisk advertises in SDP. Without this, containers advertise ; their internal bridge IP and RTP arrives at an unroutable address — the ; classic "call connects but there is no audio" failure. external_media_address = {{ asterisk_external_ip }} external_signaling_address = {{ asterisk_external_ip }} local_net = {{ asterisk_local_net }} ; --------------------------------------------------------------------------- ; Hold Slayer endpoint ; --------------------------------------------------------------------------- ; Hold Slayer authenticates as this endpoint to place calls into the lab. ; Identify the endpoint by source address. Asterisk's default matching uses ; the From-header domain, which Hold Slayer populates from its SIP bind ; address (0.0.0.0 on a wildcard bind) — never a value Asterisk can match. ; Matching on where the packet actually came from sidesteps that. [hold-slayer] type = identify endpoint = hold-slayer match = {{ asterisk_match_host }} [hold-slayer] type = endpoint context = hold-slayer-lab disallow = all ; ulaw first: it is what the PSTN uses, so the lab exercises the same codec ; path a real trunk would. alaw as fallback. allow = ulaw allow = alaw auth = hold-slayer-auth aors = hold-slayer ; RFC 2833 out-of-band DTMF — what send_dtmf must produce. Setting this ; explicitly (rather than `auto`) means a DTMF failure is a real failure and ; not a negotiation fallback quietly rescuing it. dtmf_mode = rfc4733 direct_media = no force_rport = yes rewrite_contact = yes rtp_symmetric = yes [hold-slayer-auth] type = auth auth_type = userpass username = {{ asterisk_sip_username }} password = {{ asterisk_sip_password }} [hold-slayer] type = aor max_contacts = 2 remove_existing = yes qualify_frequency = 60