RedMax EXtreme EX-LRT Anleitung zur Fehlerbehebung Seite 41

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 142
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 40
Oracle SBC Security Guide
The recommended values for these media-manager parameters for each test scenario are listed later by
system model.
Parameter
Value
fragment-msg-bandwidth
Fragment messages bandwidth limitation (in Bytes
per second)
Untrusted and fragmented packets share the same amount of bandwidth for policing.
In this appendix, it recommends the lowest possible max-untrusted-signaling for optimal DDoS
prevention. As a result, any flood of packets from an untrusted endpoint could cause untrusted bandwidth
to be exhausted and further it will trigger the Net-Net SBC to drop fragment packets in the untrusted
queue.
If the SBC is required to serve fragmented packets and to prevent fragmented packet loss, then a separate
policing queue (separate from queues that serve untrusted packets) is necessary. The main factors for
UDP fragmentation are MTU of network entities and size of SIP message transported on UDP. Applying
an appropriate value for fragment-msg-bandwidth, is based on a level of fragmentation that exists
within the network which vary greatly from one network to another. Since fragmentation is not
uncommon, an estimated value (5% of max-signaling-bandwidth) MAY be allocated to a
dedicated fragment queue in order to prevent fragment packet loss.
In releases after 7.1.2 this setting is handled automatically and does not need to be set. As a matter of fact,
it is not present in the configuration settings.
The following are Media Manager parameters that have platform specific defaults.
Parameter
min-media-allocation
min-trusted-allocation
Deny-allocation
For this appendix, these defaults will be used and are indicated in the platform results later by system
model.
Realm Configuration
The following realm-config parameters are used in the basic DDoS configuration. Only the bold
values are changes from the default configuration:
Parameter
Peer Realm
Core Realm
access-control-trust-level
high
high
invalid-signal-threshold
0
0
average-rate-limit
0
0
maximum-signal-threshold
0
0
untrusted-signal-threshold
0
0
SIP Interface
Seitenansicht 40
1 2 ... 36 37 38 39 40 41 42 43 44 45 46 ... 141 142

Kommentare zu diesen Handbüchern

Keine Kommentare