by williamconley » Tue Aug 09, 2011 11:33 am
OK, now you have my attention. My recollection of Citrix was "remote access" not "virtual environment", so please enlighten me there a bit if you will.
And YES that's a security risk, which is why Kumba issued a Security Alert on the Vicibox Board to fix it.
In theory, the trunkinbound context should be where all sip calls land ... BUT "unauthenicated" (ie: guest) will use the default context instead: the default context in sip.conf is set to "default" instead of "trunkinbound".
Changing that could have an unknown effect on the rest of the system, so it is easier to require authentication for all inbound calls. If all sip.conf contexts require user/pass (with hard-to-crack user/pass!) or have specified host IPs ... then turning off guest will point all sip calls to the contexts specified in each sip peer's "context=" value. Since agents are in "default" but have user/pass, they are assumed safe. All carriers should be assigned "trunkinbound" so they are safe because "trunkinbound" will ONLY go to the agi for inbound calls in Vicidial (no way out).
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294