IRC log for #asterisk on 20180104

00:10.41*** join/#asterisk pppingme (~pppingme@unaffiliated/pppingme)
00:51.15*** join/#asterisk pvoigt (~Linux@unaffiliated/pvoigt)
00:57.59*** join/#asterisk babak (uid19622@gateway/web/
01:07.23*** join/#asterisk chris349 (
01:08.13chris349Does anyone know how to force a Digium phone to take an extension? I reset it to default and its stuck at a screen that says "select your name and extension" but the list is empty, there is no name/extension to select.
01:08.32chris349I already did a reset to factory defaults
01:15.20*** join/#asterisk clopez_ (
01:19.56*** join/#asterisk infobot (
01:19.56*** topic/#asterisk is #asterisk The Open Source PBX and Telephony Platform ( -=- LTS: 13.18.5 (2017/12/22), Standard: 15.1.5 (2017/12/22); DAHDI: DAHDI-linux 2.11.1 (2016/03/01), DAHDI-tools 2.11.1 (2016/03/01); libpri 1.6.0 (2017/01/27) -=- Wiki: -=- Code of Conduct: -=- Logs:
01:21.56*** join/#asterisk Typhon (
01:26.56*** join/#asterisk AndyCap (~aoy@pdpc/supporter/sustaining/AndyCap)
01:31.25*** join/#asterisk awkwardpenguin (
01:45.59*** join/#asterisk freebs (~freebs@unaffiliated/freebs)
02:24.47*** join/#asterisk freebs (~freebs@unaffiliated/freebs)
02:36.56*** join/#asterisk luckman212 (~luckman21@unaffiliated/luckman212)
02:45.26*** join/#asterisk freebs (~freebs@unaffiliated/freebs)
03:04.05*** join/#asterisk awkwardpenguin (
03:20.38*** join/#asterisk awkwardpenguin (
05:29.46*** join/#asterisk cemotyz09 (
06:02.33*** join/#asterisk startledmarmot (
06:38.43*** join/#asterisk awkwardpenguin (
06:56.40*** join/#asterisk Kobaz (
07:02.06*** join/#asterisk awkwardpenguin (
07:23.38*** join/#asterisk awkwardpenguin (
07:42.41*** join/#asterisk [TK]D-Fender (~joe@
07:54.56*** join/#asterisk sekil (
08:00.11*** join/#asterisk tzafrir (
08:28.17*** join/#asterisk pchero_work (~pchero@
08:52.57*** join/#asterisk awkwardpenguin (
09:05.55*** join/#asterisk DanB (
09:08.35*** join/#asterisk DanB (
09:29.26*** join/#asterisk hehol (
09:31.01*** join/#asterisk babak (uid19622@gateway/web/
09:40.43*** join/#asterisk Worldexe (
10:30.39*** join/#asterisk sekil (
10:55.10*** join/#asterisk awkwardpenguin (
10:58.39*** join/#asterisk defsdoor (
11:30.58*** join/#asterisk pvoigt (~Linux@unaffiliated/pvoigt)
11:36.24*** join/#asterisk pvoigt (~Linux@unaffiliated/pvoigt)
11:53.29*** join/#asterisk lankanmon (~LKNnet@
12:18.32*** join/#asterisk sekil (~sekil@
12:22.01*** join/#asterisk drathir (~kamiljk8@unaffiliated/drathir)
12:24.01*** join/#asterisk dadrc (~quassel@unaffiliated/dadrc)
13:27.29*** join/#asterisk miralin (~Thunderbi@
13:57.04*** join/#asterisk awkwardpenguin (
13:59.27*** join/#asterisk brad_mssw (~brad@
14:14.13*** join/#asterisk u0m3_ (~u0m3@
14:14.46*** join/#asterisk sekil (
14:23.58*** join/#asterisk Worldexe (
14:25.45*** join/#asterisk Worldexe_ (
14:29.39*** join/#asterisk rwb (~Thunderbi@
14:47.33*** join/#asterisk tehgooch (~tehgooch@unaffiliated/tehgooch)
15:11.44*** join/#asterisk kharwell (kharwell@nat/digium/x-ojtfgxarweoowwvb)
15:11.44*** mode/#asterisk [+o kharwell] by ChanServ
15:17.33*** join/#asterisk jkroon (~jkroon@
15:25.40*** join/#asterisk bford (d8cff501@gateway/web/freenode/ip.
15:25.41*** mode/#asterisk [+o bford] by ChanServ
15:33.31*** join/#asterisk awkwardpenguin (
15:33.33*** join/#asterisk rwb1 (~Thunderbi@
15:40.51*** join/#asterisk babak (uid19622@gateway/web/
15:44.31*** join/#asterisk cresl1n (Adium@asterisk/libpri-and-libss7-expert/Cresl1n)
15:44.31*** mode/#asterisk [+o cresl1n] by ChanServ
15:58.47*** join/#asterisk jkroon (~jkroon@
16:00.45*** join/#asterisk rmudgett (rmudgett@nat/digium/x-lumhcnpzumoouyzi)
16:00.45*** mode/#asterisk [+o rmudgett] by ChanServ
16:00.58*** join/#asterisk luckman212 (~luckman21@unaffiliated/luckman212)
16:24.51Samotfile: What option is updated in the voicemail MIF to show it is an urgent message? Is the priority set to 1 or another number or does the flag= option get set to something?
16:24.59fileno idea.
16:26.13SamotWell shoot.
16:29.42*** join/#asterisk wonderworld (
16:32.06wonderworldhi, i am trying to secure asterisk in the proper way but i am failing miserably. i tried to permit/deny and contactpermit/deny everything to the ipranges i need, set allowguest=no and use strong passwords. still somehow an unknown ip managed to register to one of my peers. i really have now idea what is going on? config here:
16:32.53*** join/#asterisk gtrmtx (
16:33.38wonderworldi am having a hard time also understanding what the differnece between deny and contactdeny is. as i understand contactdeny would disallow registrations from ip-ranges (which doesn't seem to work for me). what does a simple "deny" do?
16:41.56Samotdeny/permit are for over all access.
16:42.18SamotI don't need to be registered to make a call to Asterisk.
16:42.51SamotThat's why there is an auth process (unless you set insecure=invite).
16:43.12Samotcontactdeny means I can't save my location for Asterisk to send calls to
16:45.09*** join/#asterisk jastapleton (
16:45.18wonderworldok, so my syntax must be wrong, because someone from outside of my defined ip ranges was able to auth?
16:46.51SamotI would need to see the logs of that call to see what happened.
16:47.18wonderworldok, i'll try to find them. does my config look OK to you?
16:48.21Samotpermit=    ; ALLOW IP-range of SIP provider
16:48.36SamotWhat does your SIP provider need a /24 for service?
16:49.11wonderworldno, i could tighten that more. but the ip that registered was from a completely different range
16:49.15SamotAre they sending/accepting calls over 254 addresses?
16:49.34wonderworldsorry authed
16:50.21SamotAll of your device peers are like the example [11]?
16:51.33SamotWhere is your localnet and externaladdr stuff?
16:52.07wonderworldok, i don't have that. would i need it?
16:52.41SamotWell, your PBX is behind NAT?
16:54.27SamotAll of your devices/phones are on the same local network as the PBX?
16:55.07wonderworldyes. i just want to leave things open because some people are going to be traveling and need to access the pbx from outside in the future
16:56.53wonderworldmaybe things would be more simple if i would just setup some iptables rules?
17:00.08SamotSo if you are going to have people traveling and accessing the PBX remotely having deny/permit rules is going to mess with that.
17:00.36SamotBut if the PBX is behind NAT, it should have the externaladdr set to the WAN IP
17:00.53SamotAnd the localnet set to the LAN networks that are "local" to the PBX
17:01.04Samoti.e. don't need the WAN/external details.
17:01.45SamotI would be handling this in the firewall and/or with iptables on the server.
17:02.01SamotYou can have iptables do rate limiting/checking, blocking, etc.
17:02.13wonderworldok, i setup everything according to the documentation our sip provider provided. they didn't mention localnet and externaladdr in their documentation. but if it would solve my security problems, i would add them.
17:02.22SamotWhen you are "scanned/hit" they don't just send 1 attempt
17:02.30SamotThey send 100's in a short burst.
17:02.41wonderworldyeah, i already setup fail2ban which seems to work
17:02.43SamotYou can use rate limiting to handle that.
17:02.49Samotfail2ban is reactive.
17:02.50wonderworldcatched 8 or 9 bots already
17:02.54SamotIt looks at logs.
17:02.54wonderworldthas why
17:03.11SamotSo in order for fail2ban to do anything it needs to read logs.
17:03.22wonderworldit does
17:03.23SamotIf it makes it to the logs, it's already to late.
17:03.33SamotIf you are being hit hard
17:03.42SamotAnd fail2ban can't read the logs ....
17:03.55wonderworldi setup really secure passwords... 15 letters like IGHI6tjuzbgugziuFh
17:03.55*** join/#asterisk [TK]D-Fender (~joe@
17:04.00Samotiptables does this at the system level.
17:04.08*** join/#asterisk startledmarmot (
17:04.12SamotIf I flood you with 1500 requests...
17:04.14wonderworldi guess it should be impossible to bruteforce, but still they somehow made it
17:04.52wonderworldbut i understand that the UDP flood is faster than fail2ban reading the logs.
17:05.40wonderworldso you think externaladdr and localnet would make my permit deny rules work?
17:06.28[TK]D-Fendernot related.
17:06.36[TK]D-Fenderpermit & deny are their own thing.
17:08.28Samot1) The PBX is behind NAT, externaladdr and localnet are kinda important for that
17:08.39wonderworldok, i have been searching the logs and could't find a successful auth. the way i realized something went wrong was, when i did "sip show peers" in CLI and one of my peers had that outside ip address
17:08.58SamotThat is a REGISTER
17:09.10SamotIf Asterisk has a peer location, they registered.
17:10.07wonderworldso nothing went wrong? permit/deny were working?
17:10.20SamotI don't know.
17:10.29SamotBut if you did "sip show peers"
17:10.38SamotAnd a device had a peer listed...
17:10.55SamotThat's an indicator they REGISTERed.
17:11.12SamotWhich means they auth'd.
17:11.47*** join/#asterisk jamesaxl (~James_Axl@
17:11.56wonderworldand that should be impossible with my permit deny rules?
17:12.02[TK]D-FenderWhere are the configs to look at?
17:12.58[TK]D-Fenderand the status dump for the peer...
17:15.16wonderworldhow would i generate that?
17:15.40[TK]D-Fender"sip show peer X"
17:16.48*** join/#asterisk awkwardpenguin (
17:17.18wonderworldthats the peer they managed to register or auth to ->
17:18.35[TK]D-FenderAddr->IP     : (null)
17:18.39[TK]D-Fendernot currently.
17:18.54SamotThat doesn't help if they aren't registered now
17:19.03SamotShow the peer settings from sip.conf
17:19.11[TK]D-FenderSamot, previous PB
17:19.27SamotThat was 11
17:19.29[TK]D-FenderOf course I don't like seeing 11 in one, and 12 in another
17:19.30SamotThis is 12
17:19.33SamotNot the same.
17:19.41SamotI want confirmation.
17:19.42[TK]D-FenderMy trust factor for redacted shit goes right out the window
17:20.17*** join/#asterisk jkroon (~jkroon@
17:20.41wonderworldsorry guys, phone, back in a minute
17:24.50wonderworldpeer 12 ->
17:26.12[TK]D-FenderAre ANY of them still showing any signs of the outside having registered?
17:26.40wonderworldnope. i became afraid and restarted the box and added the ip's in question manualy to iptables
17:32.08jamesaxlDay after Day, I improve voip server features, I thank [TK]D-Fender Samot for many helps.
17:34.36jamesaxl[TK]D-Fender Samot gift =>
17:39.10*** join/#asterisk Typhon (
17:49.11*** join/#asterisk jastapleton_ (~jastaplet@
17:55.00*** join/#asterisk clarjon1 (~clarjon1@unaffiliated/clarjon1)
17:56.42*** join/#asterisk Dovid (
17:58.07*** join/#asterisk Iamnacho (
18:01.45*** join/#asterisk tzafrir (
18:21.10*** join/#asterisk salviadud (
18:37.40*** join/#asterisk pchero (~pchero@
18:44.28*** join/#asterisk giesen (~ggiesen@2001:19f0:0:1019:5400:ff:fe25:bda6)
18:47.01*** join/#asterisk RovingWriter (~RovingWri@unaffiliated/rovingwriter)
18:49.21*** join/#asterisk mlhess (
18:59.17*** join/#asterisk chandoo (
18:59.35chandoohow to use OAuth with googlevoice in Asterisk 15
19:00.07chandooit is asking for refresh token, client id and secret , how to generate these
19:00.11chandoofor google voice
19:04.01filethere is information in the sample config
19:08.36chandoohow to generate OAuth Client ID and secret , can i makeup my own? and input them at both locations?
19:09.01filethat is in that same sample config, a few line sdown
19:10.00*** join/#asterisk giesen (~ggiesen@2001:19f0:0:1019:5400:ff:fe25:bda6)
19:16.56*** join/#asterisk jastapleton_ (
19:48.53chandoo`secret` must NOT be set if you use OAuth
19:49.09chandoois that mean i have to set refresh token and client id only?
20:00.03fileoauth_secret, oauth_clientid, and refresh_token must be set.
20:20.25chandooi put all three details
20:20.31chandoostatus shows disconnected
20:20.38chandooi restarted amportal
20:20.47chandoodo i need to reboot the server?
20:27.22*** join/#asterisk babak (uid19622@gateway/web/
20:28.16*** join/#asterisk defsdoor (
20:29.42*** join/#asterisk rwb (~Thunderbi@
20:31.28*** join/#asterisk startledmarmot (
20:38.01*** join/#asterisk bmg505 (
21:09.14*** join/#asterisk Dovid (
21:30.38*** join/#asterisk startledmarmot (
21:31.25*** join/#asterisk startledmarmot (
21:32.12*** join/#asterisk startledmarmot (
21:32.45*** join/#asterisk freebs (~freebs@unaffiliated/freebs)
21:32.58*** join/#asterisk startledmarmot (
21:33.48*** join/#asterisk startledmarmot (
21:34.32*** join/#asterisk startledmarmot (
21:38.18*** join/#asterisk luckman212 (~luckman21@unaffiliated/luckman212)
21:40.05*** join/#asterisk elguero (
21:51.45*** join/#asterisk ch4plin (~ch4plin@2806:101e:6:2faf:5971:387e:d01b:c6cc)
21:53.25ch4plinhi everyone! I installed an asterisk box using a sangome card with openr2. Just a quick question, the customer is telling if is possible to volume up the call, is it possible?
22:15.08*** join/#asterisk awkwardpenguin (
22:16.12[TK]D-Fendercheck your gain settings in your dahdi configs
22:49.18*** part/#asterisk gtrmtx (
22:54.43*** join/#asterisk TandyUK2 (~admin@TandyUK/staff/James)
22:57.00ch4plin[TK]D-Fender: you mean, to increase the rx/tx parameters?
23:19.09*** join/#asterisk Zanelos (~zach@
23:21.00*** join/#asterisk paulgrmn__ (~paulgrmn@
23:52.46*** part/#asterisk znoteer_ (~Wang@
23:53.03*** join/#asterisk Zanelos (~zach@

Generated by Modified by Tim Riker to work with infobot.