Help! - Cisco PIX - breaks SIP Digest authentication
DComTalk.com Forum Index DComTalk.com
Discussion of VoIP, VPN, Video Conferencen, DSL and other data commucations.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web dcomtalk.com
Help! - Cisco PIX - breaks SIP Digest authentication

 
Post new topic   Reply to topic    DComTalk.com Forum Index -> VoIP
Author Message
Mike Bromwich
Guest





Posted: Mon Oct 04, 2004 2:09 am    Post subject: Help! - Cisco PIX - breaks SIP Digest authentication Reply with quote

Hi

I have a SIP proxy server behind a Cisco PIX box, and need external
UAs to be able to place calls through it. Since the SIP proxy handles
the required address translations, I do not need the PIX to do any
fixup. I have therefore disabled the fixup in the configuration file.

However, the PIX is still insisting on replacing the IP address in the
URI part of the digest authentication header. Since the URI forms part
of the data over which the MD5 digest is calculated, this in turn
invalidates the authentication response and authentication fails.

If I connect the proxy directly to the internet (i.e. bypass the PIX),
then the authentication works fine.

Is there any way to stop the PIX interferring here? It appears that
there is no way to disable the SIP fixup for UDP-encapsulated SIP - I
found this on the Cisco site...

'Application inspection of UDP for SIP is always enabled—it is
currently not configurable.'

If this is the case, how can digest authentication for SIP ever work
through a PIX?

Mike
Back to top
 
Post new topic   Reply to topic    DComTalk.com Forum Index -> VoIP All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




VoIP Solutions: Telephone Systems Electronics Satellite TV Tech & Gadgets
Powered by phpBB