Configure SIP Access Control
When you are configuring SIP Access Control, you are essentially controlling what entities on the Internet can contact Genesys Cloud using either an External SIP trunk, a SIP Phone trunk, or a BYOC Cloud trunk.
External SIP trunk or SIP Phone trunk
For an External SIP trunk or a SIP Phone trunk, you configure SIP Access Control by building an allowlist or denylist consisting of IP or CIDR addresses that are either allowed to or prevented from using the External SIP or SIP phone trunk.
While you can enter addresses in both lists, it is a Genesys Cloud best practice to try to configure SIP Access Control List primarily using an allowlist via the Allow the Following Addresses list. The reason being is that allowlist operations take place early in the system processing and require less overhead relative to the denylist operations.
- Click Admin.
- Under Telephony, click Trunks.
- Click the appropriate tab: External Trunks or Phone Trunks.
- From the list, select the trunk you want to configure.
- Under SIP Access Control > Use Source Address
- Set the switch to Yes, if you want the ACL matching to use the SIP message source address.
- Set the switch to No, if you want to the ACL matching to use the VIA header originating address.
- To add an address to the Allow the Following Addresses list, enter that address in the Add an IP or CIDR address box and click Plus .
- To add an address to the Always Deny the Following Addresses list, enter that address in the Add an IP or CIDR address box and click Plus .
- Leave the Allow All check box blank.
- Click Save External Trunk or Save Phone Trunk.
BYOC Cloud trunk
For a BYOC Cloud trunk (BYOC Carrier or BYOC PBX), you configure SIP Access Control by building an allowlist consisting of IP or CIDR addresses that are allowed to use the BYOC Cloud trunk. There isn’t a denylist for BYOC Cloud trunks.
- Click Admin.
- Under Telephony, click Trunks.
- Click the External Trunks tab.
- From the list, select the BYOC Cloud trunk you want to configure.
- Under SIP Access Control, add an address to the Allow the Following Addresses list by entering that address in the Add an IP or CIDR address box and clicking Plus .
- Click Save External Trunk.