Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!KAMAILIO
- #
- # Kamailio (OpenSER) SIP Server v5.4 - default configuration script
- # - web: https://www.kamailio.org
- # - git: https://github.com/kamailio/kamailio
- #
- # Direct your questions about this file to: <[email protected]>
- #
- # Refer to the Core CookBook at https://www.kamailio.org/wiki/
- # for an explanation of possible statements, functions and parameters.
- #
- # Note: the comments can be:
- # - lines starting with #, but not the pre-processor directives,
- # which start with #!, like #!define, #!ifdef, #!endif, #!else, #!trydef,
- # #!subst, #!substdef, ...
- # - lines starting with //
- # - blocks enclosed in between /* */
- # Note: the config performs symmetric SIP signaling
- # - it sends the reply to the source address of the request
- # - remove the use of force_rport() for asymmetric SIP signaling
- #
- # Several features can be enabled using '#!define WITH_FEATURE' directives:
- #
- # *** To run in debug mode:
- #!define WITH_DEBUG
- # - debug level increased to 3, logs still sent to syslog
- # - debugger module loaded with cfgtrace endabled
- #
- # *** To enable mysql:
- # - define WITH_MYSQL
- #
- # *** To enable authentication execute:
- # - enable mysql
- #!define WITH_AUTH
- # - add users using 'kamctl' or 'kamcli'
- #
- # *** To enable IP authentication execute:
- # - enable mysql
- # - enable authentication
- #!define WITH_IPAUTH
- # - add IP addresses with group id '1' to 'address' table
- #
- # *** To enable persistent user location execute:
- # - enable mysql
- #!define WITH_USRLOCDB
- #
- # *** To enable presence server execute:
- # - enable mysql
- # - define WITH_PRESENCE
- # - if modified headers or body in config must be used by presence handling:
- # - define WITH_MSGREBUILD
- #
- # *** To enable nat traversal execute:
- #!define WITH_NAT
- # - option for NAT SIP OPTIONS keepalives: WITH_NATSIPPING
- # - install RTPProxy: http://www.rtpproxy.org
- # - start RTPProxy:
- # rtpproxy -l _your_public_ip_ -s udp:localhost:7722
- #
- # *** To use RTPEngine (instead of RTPProxy) for nat traversal execute:
- #!define WITH_RTPENGINE
- # - install RTPEngine: https://github.com/sipwise/rtpengine
- # - start RTPEngine:
- # rtpengine --listen-ng=127.0.0.1:2223 ...
- #
- # *** To enable PSTN gateway routing execute:
- # - define WITH_PSTN
- # - set the value of pstn.gw_ip
- # - check route[PSTN] for regexp routing condition
- #
- # *** To enable database aliases lookup execute:
- # - enable mysql
- # - define WITH_ALIASDB
- #
- # *** To enable speed dial lookup execute:
- # - enable mysql
- # - define WITH_SPEEDDIAL
- #
- # *** To enable multi-domain support execute:
- # - enable mysql
- # - define WITH_MULTIDOMAIN
- #
- # *** To enable TLS support execute:
- # - adjust CFGDIR/tls.cfg as needed
- # - define WITH_TLS
- #
- # *** To enable JSONRPC over HTTP(S) support execute:
- # - define WITH_JSONRPC
- # - adjust event_route[xhttp:request] for access policy
- #
- # *** To enable anti-flood detection execute:
- # - adjust pike and htable=>ipban settings as needed (default is
- # block if more than 16 requests in 2 seconds and ban for 300 seconds)
- # - define WITH_ANTIFLOOD
- #
- # *** To block 3XX redirect replies execute:
- # - define WITH_BLOCK3XX
- #
- # *** To block 401 and 407 authentication replies execute:
- # - define WITH_BLOCK401407
- #
- # *** To enable VoiceMail routing execute:
- # - define WITH_VOICEMAIL
- # - set the value of voicemail.srv_ip
- # - adjust the value of voicemail.srv_port
- #
- # *** To enhance accounting execute:
- # - enable mysql
- # - define WITH_ACCDB
- # - add following columns to database
- #!ifdef ACCDB_COMMENT
- ALTER TABLE acc ADD COLUMN src_user VARCHAR(64) NOT NULL DEFAULT '';
- ALTER TABLE acc ADD COLUMN src_domain VARCHAR(128) NOT NULL DEFAULT '';
- ALTER TABLE acc ADD COLUMN src_ip varchar(64) NOT NULL default '';
- ALTER TABLE acc ADD COLUMN dst_ouser VARCHAR(64) NOT NULL DEFAULT '';
- ALTER TABLE acc ADD COLUMN dst_user VARCHAR(64) NOT NULL DEFAULT '';
- ALTER TABLE acc ADD COLUMN dst_domain VARCHAR(128) NOT NULL DEFAULT '';
- ALTER TABLE missed_calls ADD COLUMN src_user VARCHAR(64) NOT NULL DEFAULT '';
- ALTER TABLE missed_calls ADD COLUMN src_domain VARCHAR(128) NOT NULL DEFAULT '';
- ALTER TABLE missed_calls ADD COLUMN src_ip varchar(64) NOT NULL default '';
- ALTER TABLE missed_calls ADD COLUMN dst_ouser VARCHAR(64) NOT NULL DEFAULT '';
- ALTER TABLE missed_calls ADD COLUMN dst_user VARCHAR(64) NOT NULL DEFAULT '';
- ALTER TABLE missed_calls ADD COLUMN dst_domain VARCHAR(128) NOT NULL DEFAULT '';
- #!endif
- ####### Include Local Config If Exists #########
- import_file "kamailio-local.cfg"
- ####### Defined Values #########
- # *** Value defines - IDs used later in config
- #!ifdef WITH_DEBUG
- #!define DBGLEVEL 3
- #!else
- #!define DBGLEVEL 2
- #!endif
- #!ifdef WITH_MYSQL
- # - database URL - used to connect to database server by modules such
- # as: auth_db, acc, usrloc, a.s.o.
- #!trydef DBURL "mysql://kamailio:kamailiorw@localhost/kamailio"
- #!endif
- #!ifdef WITH_MULTIDOMAIN
- # - the value for 'use_domain' parameters
- #!define MULTIDOMAIN 1
- #!else
- #!define MULTIDOMAIN 0
- #!endif
- # - flags
- # FLT_ - per transaction (message) flags
- # FLB_ - per branch flags
- #!define FLT_ACC 1
- #!define FLT_ACCMISSED 2
- #!define FLT_ACCFAILED 3
- #!define FLT_NATS 5
- #!define FLB_NATB 6
- #!define FLB_NATSIPPING 7
- ####### Global Parameters #########
- /* LOG Levels: 3=DBG, 2=INFO, 1=NOTICE, 0=WARN, -1=ERR, ... */
- debug=DBGLEVEL
- /* set to 'yes' to print log messages to terminal or use '-E' cli option */
- log_stderror=no
- memdbg=5
- memlog=5
- log_facility=LOG_LOCAL0
- log_prefix="{$mt $hdr(CSeq) $ci} "
- /* number of SIP routing processes for each UDP socket
- * - value inherited by tcp_children and sctp_children when not set explicitely */
- children=8
- /* uncomment the next line to disable TCP (default on) */
- disable_tcp=yes
- /* number of SIP routing processes for all TCP/TLS sockets */
- # tcp_children=8
- /* uncomment the next line to disable the auto discovery of local aliases
- * based on reverse DNS on IPs (default on) */
- # auto_aliases=no
- /* add local domain aliases - it can be set many times */
- alias="pdl.sytes.net"
- /* listen sockets - if none set, Kamailio binds to all local IP addresses
- * - basic prototype (full prototype can be found in Wiki - Core Cookbook):
- * listen=[proto]:[localip]:[lport] advertise [publicip]:[pport]
- * - it can be set many times to add more sockets to listen to */
- listen=udp:10.20.7.103:5060
- #listen=udp:0.0.0.0:5060
- mhomed=1
- /* life time of TCP connection when there is no traffic
- * - a bit higher than registration expires to cope with UA behind NAT */
- tcp_connection_lifetime=3605
- /* upper limit for TCP connections (it includes the TLS connections) */
- tcp_max_connections=2048
- #!ifdef WITH_JSONRPC
- tcp_accept_no_cl=yes
- #!endif
- #!ifdef WITH_TLS
- #enable_tls=yes
- /* upper limit for TLS connections */
- tls_max_connections=2048
- #!endif
- /* set it to yes to enable sctp and load sctp.so module */
- enable_sctp=no
- ####### Custom Parameters #########
- /* These parameters can be modified runtime via RPC interface
- * - see the documentation of 'cfg_rpc' module.
- *
- * Format: group.id = value 'desc' description
- * Access: $sel(cfg_get.group.id) or @cfg_get.group.id */
- #!ifdef WITH_PSTN
- /* PSTN GW Routing
- *
- * - pstn.gw_ip: valid IP or hostname as string value, example:
- * pstn.gw_ip = "10.0.0.101" desc "My PSTN GW Address"
- *
- * - by default is empty to avoid misrouting */
- pstn.gw_ip = "" desc "PSTN GW Address"
- pstn.gw_port = "" desc "PSTN GW Port"
- #!endif
- #!ifdef WITH_VOICEMAIL
- /* VoiceMail Routing on offline, busy or no answer
- *
- * - by default Voicemail server IP is empty to avoid misrouting */
- voicemail.srv_ip = "" desc "VoiceMail IP Address"
- voicemail.srv_port = "5060" desc "VoiceMail Port"
- #!endif
- ####### Modules Section ########
- /* set paths to location of modules */
- # mpath="/usr/lib/x86_64-linux-gnu/kamailio/modules/"
- #!ifdef WITH_MYSQL
- #loadmodule "db_mysql.so"
- #!endif
- #!ifdef WITH_JSONRPC
- loadmodule "xhttp.so"
- #!endif
- loadmodule "jsonrpcs.so"
- loadmodule "kex.so"
- loadmodule "corex.so"
- loadmodule "tm.so"
- loadmodule "tmx.so"
- loadmodule "sl.so"
- loadmodule "rr.so"
- loadmodule "pv.so"
- loadmodule "maxfwd.so"
- loadmodule "usrloc.so"
- loadmodule "registrar.so"
- loadmodule "textops.so"
- loadmodule "textopsx.so"
- loadmodule "siputils.so"
- loadmodule "xlog.so"
- loadmodule "sanity.so"
- loadmodule "ctl.so"
- loadmodule "cfg_rpc.so"
- loadmodule "acc.so"
- loadmodule "counters.so"
- loadmodule "db_postgres.so"
- loadmodule "dialog.so"
- loadmodule "uac.so"
- loadmodule "htable.so"
- #!define DBURL "postgres://kamailio:[email protected]:5432/kamailio"
- #!ifdef WITH_AUTH
- loadmodule "auth.so"
- loadmodule "auth_db.so"
- #!ifdef WITH_IPAUTH
- loadmodule "permissions.so"
- #!endif
- #!endif
- #!ifdef WITH_ALIASDB
- loadmodule "alias_db.so"
- #!endif
- #!ifdef WITH_SPEEDDIAL
- loadmodule "speeddial.so"
- #!endif
- #!ifdef WITH_MULTIDOMAIN
- loadmodule "domain.so"
- #!endif
- #!ifdef WITH_PRESENCE
- loadmodule "presence.so"
- loadmodule "presence_xml.so"
- #!endif
- #!ifdef WITH_NAT
- loadmodule "nathelper.so"
- #!ifdef WITH_RTPENGINE
- loadmodule "rtpengine.so"
- #!else
- loadmodule "rtpproxy.so"
- #!endif
- #!endif
- #!ifdef WITH_TLS
- loadmodule "tls.so"
- #!endif
- #!ifdef WITH_ANTIFLOOD
- loadmodule "htable.so"
- loadmodule "pike.so"
- #!endif
- #!ifdef WITH_DEBUG
- loadmodule "debugger.so"
- #!endif
- # ----------------- setting module-specific parameters ---------------
- # ----- jsonrpcs params -----
- modparam("jsonrpcs", "pretty_format", 1)
- /* set the path to RPC fifo control file */
- # modparam("jsonrpcs", "fifo_name", "/run/kamailio/kamailio_rpc.fifo")
- /* set the path to RPC unix socket control file */
- # modparam("jsonrpcs", "dgram_socket", "/run/kamailio/kamailio_rpc.sock")
- #!ifdef WITH_JSONRPC
- modparam("jsonrpcs", "transport", 7)
- #!endif
- # ----- ctl params -----
- /* set the path to RPC unix socket control file */
- # modparam("ctl", "binrpc", "unix:/run/kamailio/kamailio_ctl")
- # ----- sanity params -----
- modparam("sanity", "autodrop", 0)
- # ----- tm params -----
- # auto-discard branches from previous serial forking leg
- modparam("tm", "failure_reply_mode", 3)
- # default retransmission timeout: 30sec
- modparam("tm", "fr_timer", 30000)
- # default invite retransmission timeout after 1xx: 120sec
- modparam("tm", "fr_inv_timer", 120000)
- # ----- rr params -----
- # set next param to 1 to add value to ;lr param (helps with some UAs)
- modparam("rr", "enable_full_lr", 0)
- # do not append from tag to the RR (no need for this script)
- modparam("rr", "append_fromtag", 1)
- # ----- registrar params -----
- modparam("registrar", "method_filtering", 1)
- /* uncomment the next line to disable parallel forking via location */
- # modparam("registrar", "append_branches", 0)
- /* uncomment the next line not to allow more than 10 contacts per AOR */
- # modparam("registrar", "max_contacts", 10)
- /* max value for expires of registrations */
- modparam("registrar", "max_expires", 3600)
- /* set it to 1 to enable GRUU */
- modparam("registrar", "gruu_enabled", 0)
- /* set it to 0 to disable Path handling */
- modparam("registrar", "use_path", 1)
- /* save Path even if not listed in Supported header */
- modparam("registrar", "path_mode", 0)
- # ----- acc params -----
- /* what special events should be accounted ? */
- modparam("acc", "early_media", 0)
- modparam("acc", "report_ack", 0)
- modparam("acc", "report_cancels", 0)
- /* by default ww do not adjust the direct of the sequential requests.
- * if you enable this parameter, be sure the enable "append_fromtag"
- * in "rr" module */
- modparam("acc", "detect_direction", 0)
- /* account triggers (flags) */
- modparam("acc", "log_flag", FLT_ACC)
- modparam("acc", "log_missed_flag", FLT_ACCMISSED)
- modparam("acc", "log_extra",
- "src_user=$fU;src_domain=$fd;src_ip=$si;"
- "dst_ouser=$tU;dst_user=$rU;dst_domain=$rd")
- modparam("acc", "failed_transaction_flag", FLT_ACCFAILED)
- /* enhanced DB accounting */
- #!ifdef WITH_ACCDB
- modparam("acc", "db_flag", FLT_ACC)
- modparam("acc", "db_missed_flag", FLT_ACCMISSED)
- modparam("acc", "db_url", DBURL)
- modparam("acc", "db_extra",
- "src_user=$fU;src_domain=$fd;src_ip=$si;"
- "dst_ouser=$tU;dst_user=$rU;dst_domain=$rd")
- #!endif
- # ----- usrloc params -----
- modparam("usrloc", "timer_interval", 60)
- modparam("usrloc", "timer_procs", 1)
- modparam("usrloc", "use_domain", MULTIDOMAIN)
- /* enable DB persistency for location entries */
- #!ifdef WITH_USRLOCDB
- modparam("usrloc", "db_url", DBURL)
- modparam("usrloc", "db_mode", 1)
- #!endif
- # ----- auth_db params -----
- #!ifdef WITH_AUTH
- modparam("auth_db", "db_url", DBURL)
- modparam("auth_db", "calculate_ha1", yes)
- modparam("auth_db", "password_column", "password")
- modparam("auth_db", "load_credentials", "")
- modparam("auth_db", "use_domain", MULTIDOMAIN)
- # ----- permissions params -----
- #!ifdef WITH_IPAUTH
- modparam("permissions", "db_url", DBURL)
- modparam("permissions", "db_mode", 1)
- #!endif
- #!endif
- # ----- alias_db params -----
- #!ifdef WITH_ALIASDB
- modparam("alias_db", "db_url", DBURL)
- modparam("alias_db", "use_domain", MULTIDOMAIN)
- #!endif
- # ----- speeddial params -----
- #!ifdef WITH_SPEEDDIAL
- modparam("speeddial", "db_url", DBURL)
- modparam("speeddial", "use_domain", MULTIDOMAIN)
- #!endif
- # ----- domain params -----
- #!ifdef WITH_MULTIDOMAIN
- modparam("domain", "db_url", DBURL)
- /* register callback to match myself condition with domains list */
- modparam("domain", "register_myself", 1)
- #!endif
- #!ifdef WITH_PRESENCE
- # ----- presence params -----
- modparam("presence", "db_url", DBURL)
- # ----- presence_xml params -----
- modparam("presence_xml", "db_url", DBURL)
- modparam("presence_xml", "force_active", 1)
- #!endif
- #!ifdef WITH_NAT
- #!ifdef WITH_RTPENGINE
- # ----- rtpengine params -----
- modparam("rtpengine", "rtpengine_sock", "udp:127.0.0.1:2223")
- #!else
- # ----- rtpproxy params -----
- modparam("rtpproxy", "rtpproxy_sock", "udp:127.0.0.1:7722")
- #!endif
- # ----- nathelper params -----
- modparam("nathelper", "natping_interval", 30)
- modparam("nathelper", "ping_nated_only", 1)
- modparam("nathelper", "sipping_bflag", FLB_NATSIPPING)
- modparam("nathelper", "sipping_from", "sip:[email protected]")
- # params needed for NAT traversal in other modules
- modparam("nathelper|registrar", "received_avp", "$avp(RECEIVED)")
- modparam("usrloc", "nat_bflag", FLB_NATB)
- #!endif
- #!ifdef WITH_TLS
- # ----- tls params -----
- modparam("tls", "config", "/etc/kamailio/tls.cfg")
- #!endif
- #!ifdef WITH_ANTIFLOOD
- # ----- pike params -----
- modparam("pike", "sampling_time_unit", 2)
- modparam("pike", "reqs_density_per_unit", 16)
- modparam("pike", "remove_latency", 4)
- # ----- htable params -----
- /* ip ban htable with autoexpire after 5 minutes */
- modparam("htable", "htable", "auth=>size=10;autoexpire=1800;")
- modparam("htable", "htable", "ipban=>size=10;autoexpire=300;initval=0;")
- modparam("auth_db", "load_credentials", "$avp(pass)=password")
- #!endif
- #!ifdef WITH_DEBUG
- # ----- debugger params -----
- modparam("debugger", "cfgtrace", 1)
- modparam("debugger", "log_level_name", "exec")
- #!endif
- ###################
- # ----- dialog params -----
- modparam("dialog", "dlg_flag", 0)
- modparam("dialog", "default_timeout", 21600)
- modparam("dialog", "db_url", DBURL)
- modparam("dialog", "db_mode", 1)
- modparam("dialog", "send_bye", 1)
- modparam("dialog", "ka_timer", 3)
- modparam("dialog", "ka_interval", 30)
- modparam("dialog", "ka_failed_limit", 1)
- modparam("dialog", "track_cseq_updates", 1)
- ###################
- modparam("uac", "reg_db_url", DBURL)
- #modparam("uac","auth_username_avp","$avp(auser)")
- #modparam("uac","auth_password_avp","$avp(apass)")
- #modparam("uac","auth_realm_avp","$avp(arealm)")
- modparam("uac", "reg_db_table", "uacreg")
- modparam("uac", "reg_timer_interval",20)
- modparam("uac", "reg_retry_interval",120)
- modparam("uac", "reg_contact_addr", "88.79.229.217:5060")
- modparam("uac", "reg_active", 1)
- modparam("uac", "restore_mode", "auto")
- ##################
- # Dispatcher (rus-kamailio-conf)
- loadmodule "dispatcher.so"
- modparam("dispatcher", "flags", 2)
- modparam("dispatcher", "ds_probing_mode", 1)
- modparam("dispatcher", "ds_ping_interval", 10) # ds_ping_interval — мы задаем периодичность отправки healtcheck
- modparam("dispatcher", "ds_probing_threshold", 4) #В приведенном примере, прежде чем SIP сервер (хост) из dispatcher списка станет недоступным, необходимо отправить два неудачных запроса.
- modparam("dispatcher", "ds_inactive_threshold", 4)
- modparam("dispatcher", "db_url", DBURL)
- ###################
- ####### Routing Logic ########
- /* Main SIP request routing logic
- * - processing of any incoming SIP request starts with this route
- * - note: this is the same as route { ... } */
- ###################################################################
- request_route {
- route(REQINIT);
- if (is_method("CANCEL")) {
- if (t_check_trans()) {
- route(RELAY);
- }
- exit;
- }
- if (is_method("INVITE") || is_method("REGISTER")) {
- route(NAT);
- }
- if (is_method("REGISTER")) {
- route(AUTH);
- }
- route(DIALOG);
- }
- #################################################################
- route[REQINIT] {
- if($sht(ipban=>$si) > 5) {
- exit;
- }
- force_rport;
- }
- ################################################################
- route[AUTH] {
- if (sht_match_name("auth", "eq", "$Au")) {
- if (!pv_auth_check("$fd", "$sht(auth=>$Au)", "0", "1")) {
- auth_challenge("$fd", "1");
- $sht(ipban=>$si) = $sht(ipban=>$si) + 1;
- exit;
- }
- consume_credentials();
- $sht(ipban=>$si) = $null;
- if (is_method("REGISTER")) {
- save("location");
- exit;
- }
- } else {
- if (!auth_check("$fd", "subscriber", "1")) {
- auth_challenge("$fd", "1");
- $sht(ipban=>$si) = $sht(ipban=>$si) + 1;
- exit;
- }
- $sht(auth=>$Au) = $avp(pass);
- $sht(ipban=>$si) = $null;
- consume_credentials();
- if (is_method("REGISTER")) {
- save("location");
- exit;
- }
- }
- }
- ###########################################################
- route[NAT] {
- if (nat_uac_test("19")) {
- if (is_method("REGISTER")) {
- set_contact_alias();
- } else {
- if(is_first_hop()) {
- set_contact_alias();
- }
- }
- }
- return;
- }
- #########################################################
- route[DIALOG] {
- if (is_method("INVITE")) {
- route(AUTH);
- if (!lookup("location")) {
- sl_send_reply("403", "Forbidden");
- exit;
- }
- handle_ruri_alias();
- record_route();
- route(RELAY);
- }
- if (has_totag()) {
- if (loose_route()) {
- handle_ruri_alias();
- route(RELAY);
- }
- }
- if (is_method("ACK")) {
- if ( t_check_trans() ) {
- route(RELAY);
- exit;
- } else {
- exit;
- }
- }
- }
- ########################################################
- route[RELAY] {
- if (has_body("application/sdp")) {
- rtpengine_manage("replace-session-connection replace-origin ICE=remove direction=internal direction=external");
- }
- t_on_reply("REPLY");
- t_relay();
- }
- #######################################################
- onreply_route[REPLY] {
- route(NAT);
- if (has_body("application/sdp")) {
- rtpengine_manage("replace-session-connection replace-origin ICE=remove direction=internal direction=external");
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement