1. Bicom Systems
  2. Solution home
  3. SERVERware
  4. HOWTOs SERVERware 5

HOWTO :: PBXware and SIPprot on CentOS / AWS EC2

PBXWARE

sudo su

passwd

passwd ec2-user


Edit /etc/ssh/sshd_config and enable permit root, password auth. Restart sshd service.


yum install wget

yum install bzip2

yum install pcre-tools

yum install killall


Open the /etc/selinux/config file and set the SELINUX mod to disabled


cd /opt/

wget https://downloads.bicomsystems.com/updates-6.1/install-script/

gunzip install-pbxware-v6.1.sh.gz

sh install-pbxware-v6.1.sh


nano /etc/systemd/system/pbxware.service


[Unit]
Description=PBXware

[Service]
Type=forking
ExecStart=/opt/pbxware/sh/pbxware start

[Install]
WantedBy=multi-user.target


nano /etc/init.d/disable-transparent-hugepages


#!/bin/sh
### BEGIN INIT INFO
# Provides:        disable-transparent-hugepages
# Required-Start:  $local_fs
# Required-Stop:
# X-Start-Before:  mongod mongodb-mms-automation-agent
# Default-Start:   2 3 4 5
# Default-Stop:    0 1 6
# Short-Description: Disable Linux transparent huge pages
# Description:     Disable Linux transparent huge pages, to improve
#                  database performance.
### END INIT INFO

case $1 in   start)
  if [ -d /sys/kernel/mm/transparent_hugepage ]; then
    thp_path=/sys/kernel/mm/transparent_hugepage
  elif [ -d /sys/kernel/mm/redhat_transparent_hugepage ]; then
    thp_path=/sys/kernel/mm/redhat_transparent_hugepage
  else
    return 0
  fi

  echo 'never' > ${thp_path}/enabled
  echo 'never' > ${thp_path}/defrag

  unset thp_path
  ;;
esac


chmod 755 /etc/init.d/disable-transparent-hugepages


sudo chkconfig --add disable-transparent-hugepages


Reboot


SIPPROT


wget https://downloads.bicomsystems.com/sipprot/updates/5.1.0/sipprot.tbz2.sh

sh sipprot.tbz2.sh


nano  /etc/systemd/system/sipprot.service


[Unit]
Description=sipPROT
[Service]
Type=exec
ExecStart=/usr/bin/sipprotd --start--background \ --pidfile "${PIDFILE}" -w 1000 --quiet
[Install]
WantedBy=default.target


Deploying sipPROT on CentOS requires one more step after the usual sipPROT installation process. We need to configure firewall log files in order for sipPROT to work properly.

This is required because, when sipPROT detects an attack it will log it into the syslog, and we need to filter those logs into a dedicated file. The path to the dedicated file is located in sipprot.conf under:

[FIREWALL_LOG]
# default destination where blocked request are logged
path = /var/log/firewall
# max size before rotating (valid suffixes B,K,M,G)
size = 50M


sipPROT will consult this filtered file ( /var/log/firewall ) and it will act according to it.

Filtering syslog on CentOS can be done with the usage of the system logger in this case it is rsyslog.

We should create file inside /etc/rsyslog.d/ called 00-sipprot.conf with the following content:

:msg,contains,"sipprot:" /var/log/firewall

&stop


This will place all messages containing word sipprot: into our firewall file.

After placing this file in /etc/rsyslog.d/ we should restart rsyslog service with systemctl restart rsyslog.service.