Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > VOIP > Help! - Cisco PIX - breaks SIP Digest authentication

Reply
Thread Tools

Help! - Cisco PIX - breaks SIP Digest authentication

 
 
Mike Bromwich
Guest
Posts: n/a
 
      10-03-2004
Hi

I have a SIP proxy server behind a Cisco PIX box, and need external
UAs to be able to place calls through it. Since the SIP proxy handles
the required address translations, I do not need the PIX to do any
fixup. I have therefore disabled the fixup in the configuration file.

However, the PIX is still insisting on replacing the IP address in the
URI part of the digest authentication header. Since the URI forms part
of the data over which the MD5 digest is calculated, this in turn
invalidates the authentication response and authentication fails.

If I connect the proxy directly to the internet (i.e. bypass the PIX),
then the authentication works fine.

Is there any way to stop the PIX interferring here? It appears that
there is no way to disable the SIP fixup for UDP-encapsulated SIP - I
found this on the Cisco site...

'Application inspection of UDP for SIP is always enabled—it is
currently not configurable.'

If this is the case, how can digest authentication for SIP ever work
through a PIX?

Mike
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ASA/PIX inside SIP Phone to outside SIP provider googlegroups@ruetsche.com Cisco 0 03-13-2010 11:40 AM
Can't locate Digest/SHA.pm cannot install Digest/SHA myalo Perl Misc 4 11-28-2007 11:10 PM
help: digest/sha2.so: no such file to load -- digest.so Tammy Mc Ruby 3 10-01-2006 01:36 AM
Authentication for Cisco VPN client on PIX (RADIUS vs. local PIX database) tejlor Cisco 2 11-25-2003 08:07 AM
Somewhat OT: HTTP Authentication - Digest EJ MCSE 0 10-24-2003 01:33 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57