Iptables will allow you to block all but your proxies from sending. It should work (slightly) faster than the FS ACL because it'll block it earlier in the packet processing.<br><br>-Steve<br><br><br><div class="gmail_quote">
On 10 June 2011 10:31, Antonio <span dir="ltr"><<a href="mailto:potxoka@gmail.com">potxoka@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
Hi,<br>
<br>
If I had thought also use iptables, but it was to know if exists<br>
something better to put the ip's (to prevent IP spoofing). Thanks.<br>
<br>
Greetings<br>
Anto<br>
<br>
El 09/06/11 16:01, Christian Benke escribió:<br>
<div><div></div><div class="h5">> ACLs definitely would not hurt. Also think about setting up a simple<br>
> firewall(e.g. Shorewall or just plain IPTables) to limit the access to<br>
> the ip's which MUST have access(e.g. SIP-Provider IPs), you can never<br>
> be sure if a software(like FreeSWITCH) doesn't have a bug that could<br>
> be exploited.<br>
><br>
> Cheers,<br>
> Christian<br>
<br>
_______________________________________________<br>
FreeSWITCH-users mailing list<br>
<a href="mailto:FreeSWITCH-users@lists.freeswitch.org">FreeSWITCH-users@lists.freeswitch.org</a><br>
<a href="http://lists.freeswitch.org/mailman/listinfo/freeswitch-users" target="_blank">http://lists.freeswitch.org/mailman/listinfo/freeswitch-users</a><br>
UNSUBSCRIBE:<a href="http://lists.freeswitch.org/mailman/options/freeswitch-users" target="_blank">http://lists.freeswitch.org/mailman/options/freeswitch-users</a><br>
<a href="http://www.freeswitch.org" target="_blank">http://www.freeswitch.org</a><br>
</div></div></blockquote></div><br><div style="visibility: hidden; left: -5000px; position: absolute; z-index: 9999; padding: 0px; margin-left: 0px; margin-top: 0px; overflow: hidden; word-wrap: break-word; color: black; font-size: 10px; text-align: left; line-height: 130%;" id="avg_ls_inline_popup">
</div>