BCP for SIP Vicious Followup
I've been thinking about the BCP used for discarding REGISTER floods from SIP Vicious. Managing User-Agent list could get a bit cumbersome and be reactive when someone changes it to Linksys. I thought about instead of checking on the unwanted User-Agent, why not match on the domain in the To or From header? The only issue here is REGEX doesn't match on negatives, so if you get 250 registrations/sec already and have 20k+ devices registered, you don't want to store all those for comarison as the BCP does.
What about using 2 sip-manip rules?
The first would have to heder rules