Blocking Numbers with CUBE

Long ago, one may have received a spam call maybe once a month. Advancing technology introduced robo calling and number spoofing. The ability to automate unsolicited calls for marketing or spam has increased the need for better posturing and filtering at the edge. This post will cover an easy way to block those calls from your network.

Contents

Overview

This post is to demonstrate a way of blocking unsolicited calls at your gateway before they enter your network. While these calls can be blocked on CUCM with some strategic partition, calling search space, and route pattern configurations, the traffic is already in your system and inside network. The overhead of dropping that traffic falls on your CUCM with a high probability of causing a DoS event to your users. A better solution is to block this traffic at the gateway before the calls enter your network.

Components Used

This configuration can be implemented on Cisco routers running CUBE.

Configuration

First we need to define the number(s) we intend to block. Think of the voice translation rules as an ACL (access control list) in which the list is assessed from the top-down format. The following configuration blocks 8675309. Unlike ACLs, there is no implicit deny at the end. If a number does not match, it is simply not translated or, in our case, it is not blocked. Additionally, the /.*/ can be used to block all numbers/matches.

voice translation-rule 3001
 rule 1 reject /8675309/

Alternatively, for a longer list of numbers, an e164-pattern-map is more efficient than individual reject rules. The main configuration below uses the pattern map.

voice class e164-pattern-map 3001
 url http://<server>/pattern-map.cfg

Basic Dial Peer Configuration Prior to Blocking

dial-peer voice 1 voip
 description SIP from ISP
 session protocol sipv2
 voice-class sip bind control source-interface GigabitEthernet0/0/1
 voice-class sip bind media source-interface GigabitEthernet0/0/1
 dtmf-relay rtp-nte
 no vad

In the configuration that follows, we are matching inbound calling numbers against our e164 pattern map file. After they match the dial-peer and before they are forwarded, the translation profile “Inbound-CallBlock” is engaged. This, in turn, references translation-rule 3002, which rejects all numbers with the wildcard match of “.*” This can be read as match “any digit repeating any number of times”.

voice translation-rule 3002
 rule 1 reject /.*/

voice translation-profile Inbound-CallBlock
 translate calling 3002

Working Dial Peer With Blocking Added

dial-peer voice 1 voip
 description Block from ISP with Blocking
 call-block translation-profile incoming Inbound-CallBlock
 call-block disconnect-cause incoming call-reject
 session protocol sipv2
 incoming calling e164-pattern-map 3001
 voice-class sip bind control source-interface GigabitEthernet0/0/1
 voice-class sip bind media source-interface GigabitEthernet0/0/1
 dtmf-relay rtp-nte
 no vad

We still need a dial-peer to match legitimate traffic destined for our network. The following dial-peer satisfies this requirement. The .T matches any calling number, but the pattern map on dial-peer 1 is a more specific match, so only numbers not in the pattern map land on dial-peer 2.

Working Dial Peer to Match Legitimate Traffic

dial-peer voice 2 voip
 description Legitimate Traffic from ISP
 session protocol sipv2
 answer-address .T
 voice-class sip bind control source-interface GigabitEthernet0/0/1
 voice-class sip bind media source-interface GigabitEthernet0/0/1
 dtmf-relay rtp-nte
 no vad

Alternative: Blocking a Small List of Numbers on a URI-Matched Dial Peer

If your dial-peers already use SIP URI matching instead of ANI-based matching (for example, to separate SIP trunks or tenants), you can add call blocking to that existing dial-peer directly, without needing an e164-pattern-map or a second dial-peer. This fits a small, static list of numbers to block, since the reject patterns live inline in the translation-rule.

voice class uri 201 sip
 host ipv4:10.10.10.1
voice translation-rule 3003
 rule 1 reject /8675309/

voice translation-profile URI-CallBlock
 translate calling 3003
dial-peer voice 3 voip
 description SIP from ISP (URI Matched)
 session protocol sipv2
 incoming uri via 201
 call-block translation-profile incoming URI-CallBlock
 call-block disconnect-cause incoming call-reject
 voice-class sip bind control source-interface GigabitEthernet0/0/1
 voice-class sip bind media source-interface GigabitEthernet0/0/1
 dtmf-relay rtp-nte
 no vad

Note: call-block only applies to the dial-peer it’s configured on. If multiple URI-matched dial-peers exist (for example, one per tenant or trunk), the call-block commands must be added to each dial-peer where blocking should apply, adding it to just one does not protect the others.

Verification

You don’t need a live call to confirm a number will be blocked. The test voice translation-rule command runs a number against a translation-rule and reports the result.

A number that matches a reject rule:

Router# test voice translation-rule 3003 8675309
 blocked on rule 1

A number that does not match any rule:

Router# test voice translation-rule 3003 5551234
5551234 Didn't match with any of rules

To confirm the rules and profiles are configured as expected:

show voice translation-rule 3003
show voice translation-profile URI-CallBlock

If you are using an e164-pattern-map, confirm the file loaded from the URL and check the number of entries:

show voice class e164-pattern-map 3001

Note: testing translation-rule 3002 isn’t useful here, since /.*/ blocks every number. In the e164-pattern-map design, the pattern map decides which numbers are blocked, so check the pattern map instead.

References

Tags: CUBE  UC 

See also

Table of Contents