<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sip invite method request flood attempt in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273625#M75057</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Its hard to say what it would have dne in the past. Threat prevent may catch it, but its further into the inspection process so it uses more CPU. Zone and DoS protection are your best options here, I think.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2019 18:09:57 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2019-06-27T18:09:57Z</dc:date>
    <item>
      <title>sip invite method request flood attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273186#M75003</link>
      <description>&lt;P&gt;I have recently been dealing with&amp;nbsp;sip invite method request flood attempt show up not only in my threatsm but also making it impossible to make calls external or external to internal calls because its trying to call a number every 4 seconds and taking all my SIP connections available. Besides blocking it on the firewall and having the ISP deadroute the called or called number is there anything else I should do?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 16:19:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273186#M75003</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2019-06-26T16:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: sip invite method request flood attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273194#M75005</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would setup Zone and DoS protection profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/8-1/dos-and-zone-protection-best-practices/dos-and-zone-protection-best-practices.html" target="_blank"&gt;https://docs.paloaltonetworks.com/best-practices/8-1/dos-and-zone-protection-best-practices/dos-and-zone-protection-best-practices.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 17:12:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273194#M75005</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-06-26T17:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: sip invite method request flood attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273207#M75012</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;A DoS Protection Policy as mentioned by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;is probably the best solution to go for something like this, but will involve a fair bit of tuning to get everything to play nice.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 18:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273207#M75012</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-06-26T18:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: sip invite method request flood attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273624#M75056</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the least I can block it through the threat prevention, but I don't know how it works, and it appears to started back when they put in the sip trunks last June. Shouldn't it be causing issues all the time with the phones?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 18:04:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273624#M75056</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2019-06-27T18:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: sip invite method request flood attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273625#M75057</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Its hard to say what it would have dne in the past. Threat prevent may catch it, but its further into the inspection process so it uses more CPU. Zone and DoS protection are your best options here, I think.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 18:09:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273625#M75057</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-06-27T18:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: sip invite method request flood attempt</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273691#M75071</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It probably has simply got to a point where the additonal load caused by this flood, and actual line of business calls, have forced you to cross your CCP limit imposed on the trunk. As long as you didn't cross your CCP limit you likely would have never thought to look at the logs to notice the issue in the first place.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 21:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/sip-invite-method-request-flood-attempt/m-p/273691#M75071</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-06-27T21:27:27Z</dc:date>
    </item>
  </channel>
</rss>

