#!KAMAILIO #!define WITH_CONFIG_DEBUG #!define WITH_AUTH ##!define WITH_DEBUG #!define WITH_POSTGRESQL #!define WITH_LCR #!define WITH_NAT # # Kamailio (OpenSER) SIP Server v4.0 - default configuration script # - web: http://www.kamailio.org # - git: http://sip-router.org # # Direct your questions about this file to: # # Refer to the Core CookBook at http://www.kamailio.org/dokuwiki/doku.php # for an explanation of possible statements, functions and parameters. # # Several features can be enabled using '#!define WITH_FEATURE' directives: # # *** To run in debug mode: # - define WITH_DEBUG # # *** To enable postgresql: # - define WITH_POSTGRESQL # # *** To enable authentication execute: # - enable mysql # - define WITH_AUTH # - add users using 'kamctl' # # *** To enable IP authentication execute: # - enable mysql # - enable authentication # - define WITH_IPAUTH # - add IP addresses with group id '1' to 'address' table # # *** To enable persistent user location execute: # - enable mysql # - define WITH_USRLOCDB # # *** To enable presence server execute: # - enable mysql # - define WITH_PRESENCE # # *** To enable database aliases lookup execute: # - enable mysql # - define WITH_ALIASDB # # *** To enable speed dial lookup execute: # - enable mysql # - define WITH_SPEEDDIAL # # *** To enhance accounting execute: # - enable mysql # - define WITH_ACCDB # - add following columns to database #!ifdef ACCDB_COMMENT ALTER TABLE acc ADD COLUMN src_user VARCHAR(64) NOT NULL DEFAULT ''; ALTER TABLE acc ADD COLUMN src_domain VARCHAR(128) NOT NULL DEFAULT ''; ALTER TABLE acc ADD COLUMN src_ip varchar(64) NOT NULL default ''; ALTER TABLE acc ADD COLUMN dst_ouser VARCHAR(64) NOT NULL DEFAULT ''; ALTER TABLE acc ADD COLUMN dst_user VARCHAR(64) NOT NULL DEFAULT ''; ALTER TABLE acc ADD COLUMN dst_domain VARCHAR(128) NOT NULL DEFAULT ''; ALTER TABLE missed_calls ADD COLUMN src_user VARCHAR(64) NOT NULL DEFAULT ''; ALTER TABLE missed_calls ADD COLUMN src_domain VARCHAR(128) NOT NULL DEFAULT ''; ALTER TABLE missed_calls ADD COLUMN src_ip varchar(64) NOT NULL default ''; ALTER TABLE missed_calls ADD COLUMN dst_ouser VARCHAR(64) NOT NULL DEFAULT ''; ALTER TABLE missed_calls ADD COLUMN dst_user VARCHAR(64) NOT NULL DEFAULT ''; ALTER TABLE missed_calls ADD COLUMN dst_domain VARCHAR(128) NOT NULL DEFAULT ''; #!endif # *** To enable nat traversal execute: # - define WITH_NAT # - install RTPProxy: http://www.rtpproxy.org # - start RTPProxy: # rtpproxy -l _your_public_ip_ -s udp:localhost:7722 # # *** To enable TLS support execute: # - adjust CFGDIR/tls.cfg as needed # - define WITH_TLS # # *** To enable XMLRPC support execute: # - define WITH_XMLRPC # - adjust route[XMLRPC] for access policy # # *** To enable anti-flood detection execute: # - adjust pike and htable=>ipban settings as needed (default is # block if more than 16 requests in 2 seconds and ban for 300 seconds) # - define WITH_ANTIFLOOD # # *** To block 3XX redirect replies execute: # - define WITH_BLOCK3XX # # *** To enable VoiceMail routing execute: # - define WITH_VOICEMAIL # - set the value of voicemail.srv_ip # - adjust the value of voicemail.srv_port # ####### Defined Values ######### # *** Value defines - IDs used later in config #!ifdef WITH_MYSQL # - database URL - used to connect to database server by modules such # as: auth_db, acc, usrloc, a.s.o. ### managed by puppet[kamailio] ### #!define DBURL "secret dburl" #!define DBASTURL "secret dbaurl" #!endif #!ifdef WITH_POSTGRESQL # - database URL - used to connect to database server by modules such # as: auth_db, acc, usrloc, a.s.o. ### managed by puppet[kamailio] ### #!define DBURL "secret dburl" #!define DBASTURL "secret dbaurl" #!endif # - the value for 'use_domain' parameters #!define MULTIDOMAIN 0 # - flags # FLT_ - per transaction (message) flags # FLB_ - per branch flags #!define FLT_ACC 1 #!define FLT_ACCMISSED 2 #!define FLT_ACCFAILED 3 #!define FLT_NATS 5 #!define FLB_NATB 6 #!define FLB_NATSIPPING 7 ####### Global Parameters ######### #!ifdef WITH_DEBUG debug=4 log_stderror=yes #!else debug=2 log_stderror=no #!endif memdbg=5 memlog=5 #log_facility=LOG_LOCAL0 log_facility=LOG_LOCAL7 fork=yes #children=4 children=16 /* uncomment the next line to disable TCP (default on) */ #disable_tcp=yes /* uncomment the next line to disable the auto discovery of local aliases based on reverse DNS on IPs (default on) */ #auto_aliases=no auto_aliases=no /* add local domain aliases */ #alias="sip.mydomain.com" ### managed by puppet[kamailio] ### /* uncomment and configure the following line if you want Kamailio to bind on a specific interface/port/proto (default bind on all available) */ ### managed by puppet[kamailio] ### listen=udp:myip:5060 listen=tcp:myip:5060 /* port to listen to * - can be specified more than once if needed to listen on many ports */ port=5060 #mhomed=1 #!ifdef WITH_TLS enable_tls=yes #!endif # life time of TCP connection when there is no traffic # - a bit higher than registration expires to cope with UA behind NAT tcp_connection_lifetime=3605 ####### Custom Parameters ######### # These parameters can be modified runtime via RPC interface # - see the documentation of 'cfg_rpc' module. # # Format: group.id = value 'desc' description # Access: $sel(cfg_get.group.id) or @cfg_get.group.id # ####### Modules Section ######## # set paths to location of modules (to sources or installation folders) #!ifdef WITH_SRCPATH mpath="modules_k:modules" #!else #mpath="/usr/local/lib/kamailio/modules_k/:/usr/local/lib/kamailio/modules/" mpath="/usr/local/lib64/kamailio/modules/" #!endif #!ifdef WITH_MYSQL loadmodule "db_mysql.so" #!endif #!ifdef WITH_POSTGRESQL loadmodule "db_postgres.so" #!endif #!ifdef WITH_LCR loadmodule "lcr.so" #!endif loadmodule "mi_fifo.so" loadmodule "kex.so" loadmodule "tm.so" loadmodule "tmx.so" loadmodule "sl.so" loadmodule "rr.so" loadmodule "pv.so" loadmodule "maxfwd.so" loadmodule "usrloc.so" loadmodule "registrar.so" loadmodule "textops.so" loadmodule "siputils.so" loadmodule "xlog.so" loadmodule "sanity.so" loadmodule "ctl.so" loadmodule "cfg_rpc.so" loadmodule "mi_rpc.so" loadmodule "acc.so" #!ifdef WITH_AUTH loadmodule "auth.so" loadmodule "auth_db.so" #!ifdef WITH_IPAUTH loadmodule "permissions.so" #!endif #!endif #!ifdef WITH_ALIASDB loadmodule "alias_db.so" #!endif #!ifdef WITH_SPEEDDIAL loadmodule "speeddial.so" #!endif #!ifdef WITH_PRESENCE loadmodule "presence.so" loadmodule "presence_xml.so" #!endif #!ifdef WITH_NAT loadmodule "nathelper.so" loadmodule "rtpproxy.so" #!endif #!ifdef WITH_TLS loadmodule "tls.so" #!endif #!ifdef WITH_ANTIFLOOD loadmodule "htable.so" loadmodule "pike.so" #!endif #!ifdef WITH_XMLRPC loadmodule "xmlrpc.so" #!endif #!ifdef WITH_DEBUG loadmodule "debugger.so" #!endif #asterisk loadmodule "uac.so" loadmodule "dispatcher.so" # ----------------- setting module-specific parameters --------------- ### managed by puppet[kamailio] ### modparam("lcr","db_url", DBURL) modparam("lcr","lcr_gw_table","lcr_gw") modparam("lcr","tag_column","tag") modparam("lcr","weight_column","weight") modparam("lcr","flags_column","flags") modparam("lcr","gw_name_column","gw_name") modparam("lcr","ip_addr_column","ip_addr") modparam("lcr","port_column","port") modparam("lcr","hostname_column","hostname") modparam("lcr","uri_scheme_column","uri_scheme") modparam("lcr","strip_column","strip") modparam("lcr","transport_column","transport") modparam("lcr","lcr_rule_table","lcr_rule") modparam("lcr","prefix_column","prefix") modparam("lcr","from_uri_column","from_uri") modparam("lcr","priority_column","priority") modparam("lcr","gw_uri_avp", "$avp(i:709)") modparam("lcr","ruri_user_avp", "$avp(i:500)") modparam("lcr", "flags_avp", "$avp(i:712)") modparam("lcr", "lcr_rule_target_table", "lcr_rule_target") #modparam("lcr", "rpid_avp", "$avp(i:302)") #modparam("^auth$|lcr", "rpid_avp", "$avp(i:302)") ### managed by puppet[kamailio] ### # ------- Load-balancer params ------ modparam("dispatcher", "db_url", DBURL) modparam("dispatcher", "table_name", "dispatcher") modparam("dispatcher", "setid_col", "setid") modparam("dispatcher", "destination_col", "destination") ## Dispatcher: Overwrite Destination address, if required. modparam("dispatcher", "force_dst", 1) ## Dispatcher: Enable Failover-Support modparam("dispatcher", "flags", 3) #modparam("dispatcher", "flags", 2) ## AVP's required for Fail-Over-Support: modparam("dispatcher", "dst_avp", "$avp(i:271)") modparam("dispatcher", "grp_avp", "$avp(i:272)") modparam("dispatcher", "cnt_avp", "$avp(i:273)") modparam("dispatcher", "hash_pvar", "$avp(273)") modparam("dispatcher", "ds_ping_from", "sip:proxy@myip") ## Try to recover disabled destinations every 15 seconds. modparam("dispatcher", "ds_ping_interval",15) ## Actively query the gateways: modparam("dispatcher", "ds_probing_mode", 0) #modparam("dispatcher", "ds_probing_mode", 1) modparam("dispatcher", "ds_ping_reply_codes", "class=2;code=403;code=404;code=484;class=3") # ----- mi_fifo params ----- modparam("mi_fifo", "fifo_name", "/tmp/kamailio_fifo") # ----- tm params ----- # auto-discard branches from previous serial forking leg modparam("tm", "failure_reply_mode", 3) # default retransmission timeout: 30sec modparam("tm", "fr_timer", 30000) # default invite retransmission timeout after 1xx: 120sec modparam("tm", "fr_inv_timer", 120000) # Don't reply automatically with "100 Trying" modparam("tm", "auto_inv_100", 1) ### managed by puppet[kamailio] ### # multihomed host so turn off modparam("tm", "reparse_on_dns_failover", 0) # ----- rr params ----- # add value to ;lr param to cope with most of the UAs modparam("rr", "enable_full_lr", 1) # do not append from tag to the RR (no need for this script) modparam("rr", "append_fromtag", 1) # ----- registrar params ----- modparam("registrar", "method_filtering", 1) /* uncomment the next line to disable parallel forking via location */ # modparam("registrar", "append_branches", 0) /* uncomment the next line not to allow more than 10 contacts per AOR */ #modparam("registrar", "max_contacts", 10) # max value for expires of registrations modparam("registrar", "max_expires", 3600) # set it to 1 to enable GRUU modparam("registrar", "gruu_enabled", 0) # ----- acc params ----- /* what special events should be accounted ? */ modparam("acc", "early_media", 0) modparam("acc", "report_ack", 0) modparam("acc", "report_cancels", 0) /* by default ww do not adjust the direct of the sequential requests. if you enable this parameter, be sure the enable "append_fromtag" in "rr" module */ modparam("acc", "detect_direction", 0) /* account triggers (flags) */ modparam("acc", "log_flag", FLT_ACC) modparam("acc", "log_missed_flag", FLT_ACCMISSED) modparam("acc", "log_extra", "src_user=$fU;src_domain=$fd;src_ip=$si;" "dst_ouser=$tU;dst_user=$rU;dst_domain=$rd") modparam("acc", "failed_transaction_flag", FLT_ACCFAILED) /* enhanced DB accounting */ #!ifdef WITH_ACCDB modparam("acc", "db_flag", FLT_ACC) modparam("acc", "db_missed_flag", FLT_ACCMISSED) modparam("acc", "db_url", DBURL) modparam("acc", "db_extra", "src_user=$fU;src_domain=$fd;src_ip=$si;" "dst_ouser=$tU;dst_user=$rU;dst_domain=$rd") #!endif # ----- usrloc params ----- /* enable DB persistency for location entries */ #!ifdef WITH_USRLOCDB modparam("usrloc", "db_url", DBURL) modparam("usrloc", "db_mode", 2) modparam("usrloc", "use_domain", MULTIDOMAIN) #!endif # ----- auth_db params ----- #!ifdef WITH_AUTH modparam("auth_db", "calculate_ha1", yes) modparam("auth_db", "load_credentials", "") modparam("auth_db", "user_column", "name") modparam("auth_db", "password_column", "sippasswd") modparam("auth_db", "db_url", DBASTURL) modparam("auth_db", "version_table", 0) # ----- permissions params ----- #!ifdef WITH_IPAUTH modparam("permissions", "db_url", DBURL) modparam("permissions", "db_mode", 1) #!endif #!endif # ----- alias_db params ----- #!ifdef WITH_ALIASDB modparam("alias_db", "db_url", DBURL) modparam("alias_db", "use_domain", MULTIDOMAIN) #!endif # ----- speedial params ----- #!ifdef WITH_SPEEDDIAL modparam("speeddial", "db_url", DBURL) modparam("speeddial", "use_domain", MULTIDOMAIN) #!endif #!ifdef WITH_PRESENCE # ----- presence params ----- modparam("presence", "db_url", DBURL) # ----- presence_xml params ----- modparam("presence_xml", "db_url", DBURL) modparam("presence_xml", "force_active", 1) #!endif #!ifdef WITH_NAT # ----- rtpproxy params ----- modparam("rtpproxy", "rtpproxy_sock", "udp:127.0.0.1:7722") # ----- nathelper params ----- modparam("nathelper", "natping_interval", 30) modparam("nathelper", "ping_nated_only", 1) modparam("nathelper", "sipping_bflag", FLB_NATSIPPING) ### managed by puppet[kamailio] ### modparam("nathelper", "sipping_from", "sip:pinger@myip") # params needed for NAT traversal in other modules modparam("nathelper|registrar", "received_avp", "$avp(RECEIVED)") modparam("usrloc", "nat_bflag", FLB_NATB) #!endif #!ifdef WITH_TLS # ----- tls params ----- modparam("tls", "config", "/usr/local/etc/kamailio/tls.cfg") #!endif #!ifdef WITH_ANTIFLOOD # ----- pike params ----- modparam("pike", "sampling_time_unit", 2) modparam("pike", "reqs_density_per_unit", 16) modparam("pike", "remove_latency", 4) # ----- htable params ----- # ip ban htable with autoexpire after 5 minutes modparam("htable", "htable", "ipban=>size=8;autoexpire=300;") #!endif #!ifdef WITH_XMLRPC # ----- xmlrpc params ----- modparam("xmlrpc", "route", "XMLRPC"); modparam("xmlrpc", "url_match", "^/RPC") #!endif #!ifdef WITH_DEBUG # ----- debugger params ----- modparam("debugger", "cfgtrace", 1) #!endif ####### Routing Logic ######## # Main SIP request routing logic # - processing of any incoming SIP request starts with this route # - note: this is the same as route { ... } request_route { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","sip body $rb\n"); #!endif # per request initial checks route(REQINIT); # NAT detection route(NATDETECT); # handle requests within SIP dialogs route(WITHINDLG); ### only initial requests (no To tag) #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","PRE CANCEL\n"); #!endif # CANCEL processing if (is_method("CANCEL")) { if (t_check_trans()) t_relay(); exit; } t_check_trans(); # authentication route(AUTH); #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO", "SCRIPT: SIP $rm from: $fu to: $ru - srcip: $si rU: $rU\n"); #!endif # record routing for dialog forming requests (in case they are routed) # - remove preloaded route headers remove_hf("Route"); if (is_method("INVITE|SUBSCRIBE")) record_route(); # account only INVITEs if (is_method("INVITE")) { setflag(FLT_ACC); # do accounting } # dispatch requests to foreign domains route(SIPOUT); ### requests for my local domains # handle presence related requests route(PRESENCE); # handle registrations route(REGISTRAR); if ($rU==$null) { # request with no Username in RURI sl_send_reply("484","Address Incomplete"); exit; } # user location service route(LOCATION); route(RELAY); } route[RELAY] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[RELAY]\n"); #!endif # enable additional event routes for forwarded requests # - serial forking, RTP relaying handling, a.s.o. if (is_method("INVITE|SUBSCRIBE")) { t_on_branch("MANAGE_BRANCH"); t_on_reply("MANAGE_REPLY"); } if (is_method("INVITE")) { t_on_failure("MANAGE_FAILURE"); } if (!t_relay()) { sl_reply_error(); } #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO", "RELAYED SIP $rm from: $fu to: $ru - srcip:$si rU:$rU fU:$fU\n"); #!endif exit; } # Per SIP request initial checks route[REQINIT] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[REQINIT]\n"); #!endif #!ifdef WITH_ANTIFLOOD # flood dection from same IP and traffic ban for a while # be sure you exclude checking trusted peers, such as pstn gateways # - local host excluded (e.g., loop to self) if(src_ip!=myself) { if($sht(ipban=>$si)!=$null) { # ip is already blocked xdbg("request from blocked IP - $rm from $fu (IP:$si:$sp)\n"); exit; } if (!pike_check_req()) { xlog("L_ALERT","ALERT: pike blocking $rm from $fu (IP:$si:$sp)\n"); $sht(ipban=>$si) = 1; exit; } } #!endif if (!mf_process_maxfwd_header("10")) { sl_send_reply("483","Too Many Hops"); exit; } if(!sanity_check("1511", "7")) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO", "Malformed SIP message from $si:$sp\n"); #!endif xlog("Malformed SIP message from $si:$sp\n"); exit; } } # Handle requests within SIP dialogs route[WITHINDLG] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[WITHINDLG]\n"); #!endif if (has_totag()) { # sequential request withing a dialog should # take the path determined by record-routing if (loose_route()) { #record_route(); if (is_method("BYE")) { setflag(FLT_ACC); # do accounting ... setflag(FLT_ACCFAILED); # ... even if the transaction fails } if ( is_method("ACK") ) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","ACK is forwarded statelessy\n"); #!endif # ACK is forwarded statelessy route(NATMANAGE); ; } route(RELAY); } else { if (is_method("SUBSCRIBE") && uri == myself) { # in-dialog subscribe requests route(PRESENCE); exit; } if ( is_method("ACK") ) { if ( t_check_trans() ) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","ACK no loose-route\n"); #!endif # no loose-route, but stateful ACK; # must be an ACK after a 487 # or e.g. 404 from upstream server t_relay(); exit; } else { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","ACK without mathcing transaction ... ignore and discard\n"); #!endif # ACK without matching transaction ... ignore and discard exit; } } #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","404 Not here\n"); #!endif sl_send_reply("404","Not here"); } exit; } } # Handle SIP registrations route[REGISTRAR] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[REGISTRAR]\n"); #!endif if (is_method("REGISTER")) { if(isflagset(FLT_NATS)) { setbflag(FLB_NATB); # uncomment next line to do SIP NAT pinging setbflag(FLB_NATSIPPING); } if (!save("location")) sl_reply_error(); # route(REGFWD); exit; } } # USER location service route[LOCATION] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[LOCATION]\n"); #!endif #!ifdef WITH_SPEEDIAL # search for short dialing - 2-digit extension if($rU=~"^[0-9][0-9]$") if(sd_lookup("speed_dial")) route(SIPOUT); #!endif #!ifdef WITH_ALIASDB # search in DB-based aliases if(alias_db_lookup("dbaliases")) route(SIPOUT); #!endif if(is_method("INVITE") && (!route(FROMASTERISK))) { # if new call from out there - send to Asterisk # - non-INVITE request are routed directly by Kamailio # - traffic from Asterisk is routed also directy by Kamailio route(TOASTERISK); exit; } $avp(oexten) = $rU; if (!lookup("location")) { $var(rc) = $rc; t_newtran(); switch ($var(rc)) { case -1: case -3: send_reply("404", "Not Found"); exit; case -2: send_reply("405", "Method Not Allowed"); exit; } } # when routing via usrloc, log the missed calls also if (is_method("INVITE")) { setflag(FLT_ACCMISSED); } } # Presence server route route[PRESENCE] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[PRESENCE]\n"); #!endif if(!is_method("PUBLISH|SUBSCRIBE")) return; #!ifdef WITH_PRESENCE if (!t_newtran()) { sl_reply_error(); exit; }; if(is_method("PUBLISH")) { handle_publish(); t_release(); } else if( is_method("SUBSCRIBE")) { handle_subscribe(); t_release(); } exit; #!endif # if presence enabled, this part will not be executed if (is_method("PUBLISH") || $rU==$null) { sl_send_reply("404", "Not here"); exit; } return; } # Authentication route route[AUTH] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[AUTH]\n"); #!endif #!ifdef WITH_AUTH # do not auth traffic from Asterisk - trusted! if(route(FROMASTERISK)) { return; } if(from_any_gw($si, 0)) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","from gateway\n"); #!endif return; } #!ifdef WITH_IPAUTH if((!is_method("REGISTER")) && allow_source_address()) { # source IP allowed return; } #!endif #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","from uri: $fu\n"); xlog("L_INFO","original uri: $ou\n"); xlog("L_INFO","source ip: $si\n"); xlog("L_INFO","from uri domain: $fd\n"); #!endif if (is_method("REGISTER") || from_uri==myself) { # authenticate requests if (!auth_check("$fd", "sipusers", "1")) { auth_challenge("$fd", "0"); exit; } # user authenticated - remove auth header if(!is_method("REGISTER|PUBLISH")) consume_credentials(); } # if caller is not local subscriber, then check if it calls # a local destination, otherwise deny, not an open relay here if (from_uri!=myself && uri!=myself) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","403, not relaying. uri: $ou\n"); #!endif sl_send_reply("403","Not relaying"); exit; } #!endif return; } # Caller NAT detection route route[NATDETECT] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[NATDETECT]\n"); #!endif #!ifdef WITH_NAT force_rport(); if (nat_uac_test("19")) { if (is_method("REGISTER")) { fix_nated_register(); } else { fix_nated_contact(); } setflag(FLT_NATS); } #!endif return; } # RTPProxy control route[NATMANAGE] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[NATMANAGE]\n"); #!endif #!ifdef WITH_NAT if (is_request()) { if(has_totag()) { if(check_route_param("nat=yes")) { setbflag(FLB_NATB); } } } if (!(isflagset(FLT_NATS) || isbflagset(FLB_NATB))) return; #route(RTPPROXY); rtpproxy_manage(); if (is_request()) { if (!has_totag()) { add_rr_param(";nat=yes"); } } if (is_reply()) { if(isbflagset(FLB_NATB)) { fix_nated_contact(); } } #!endif return; } # Routing to foreign domains route[SIPOUT] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[SIPOUT]\n"); #!endif if(from_any_gw($si, 0)) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","from gateway\n"); #!endif return; } if (uri==myself && !is_method("OPTIONS")) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","ru:$ru\n"); xlog("L_INFO","load_gws\n"); #!endif if (!load_gws(1, $rU, $var(caller_uri))) { #if (!load_gws("$var(caller_uri)")) { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","Internal server error, unable to load gateways\n"); #!endif sl_send_reply("500", "Internal server error, unable to load gateways"); exit; } #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","ru:$ru\n"); xlog("L_INFO","next_gw\n"); #!endif if (!next_gw()){ #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","Service not available, no gateways found\n"); #!endif sl_send_reply("503", "Service not available, no gateways found"); exit; } #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","ru:$ru\n"); #!endif route(RELAY); } # route(TOUPSTREAMSIP); if (!uri==myself) { append_hf("P-hint: outbound\r\n"); route(RELAY); } } # XMLRPC routing #!ifdef WITH_XMLRPC route[XMLRPC] { # allow XMLRPC from localhost if ((method=="POST" || method=="GET") && (src_ip==127.0.0.1)) { # close connection only for xmlrpclib user agents (there is a bug in # xmlrpclib: it waits for EOF before interpreting the response). if ($hdr(User-Agent) =~ "xmlrpclib") set_reply_close(); set_reply_no_connect(); dispatch_rpc(); exit; } send_reply("403", "Forbidden"); exit; } #!endif # manage outgoing branches branch_route[MANAGE_BRANCH] { xdbg("new branch [$T_branch_idx] to $ru\n"); route(NATMANAGE); } # manage incoming replies onreply_route[MANAGE_REPLY] { xdbg("incoming reply\n"); if(status=~"[12][0-9][0-9]") route(NATMANAGE); } # manage failure routing cases failure_route[MANAGE_FAILURE] { route(NATMANAGE); if (t_is_canceled()) { exit; } #!ifdef WITH_BLOCK3XX # block call redirect based on 3xx replies. if (t_check_status("3[0-9][0-9]")) { t_reply("404","Not found"); exit; } #!endif } # Test if coming from Asterisk route[FROMASTERISK] { if(ds_is_from_list()){ # rtpproxy_manage("cawie"); #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","[$fU@$si:$sp]{$rm} Call from Media-Server Cluster header: $fu\n"); #!endif return 1; } return -1; } # Send to Asterisk route[TOASTERISK] { #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","route[TOASTERISK]\n"); #!endif ds_mark_dst("P"); if(!ds_select_dst("1", "4")) { # ds_mark_dst("IP"); sl_send_reply("500", "Service Unavailable"); xlog("L_INFO","[$fU@$si:$sp]{$rm} No destinations available for $rd \n"); exit; } #!ifdef WITH_CONFIG_DEBUG xlog("L_INFO","[$fU@$si:$sp]{$rm} From Outside World to Asterisk Box $du\n"); #!endif t_on_failure("RTF_DISPATCH"); route(RELAY); exit; } # Sample failure route failure_route[RTF_DISPATCH] { if (t_is_canceled()) { exit; } # next DST - only for 500 or local timeout if (t_check_status("500") or (t_branch_timeout() and !t_branch_replied())) { if(ds_next_dst()) { t_on_failure("RTF_DISPATCH"); route(RELAY); exit; } } }