sipShield SPL Plugin Query
Hi,
I loaded the sipShield SPL plugin to my lab this week and have noticed that it's denying traffic that should be passed, specifically one user. The user in question does have an unusual display/user name however the traffic needs to pass.
It would be useful to understand what the plugin is scanning for at a low level as to disallow customers to chose problematic display/usernames.
Anyone any ideas?
ACMESBC02# sh spl sipd
SPL Version: C2.0.1
[sipd] File: sipShield.1.4.spl version: 1.4 signature: signed and valid
ACMESBC02#
ACMESBC02# sh spl-options
1. block-attack-tools: Directs the sip-interface or realm to drop common SIP attacks [config,sipShield.1.4.spl]