Actions

ProSBC:Robocall Mitigation: Difference between revisions

(NT:Created the page)
 
(NT: Correction)
 
(41 intermediate revisions by 3 users not shown)
Line 4: Line 4:
This document provides instructions on how to configure ProSBC to operate with the TransNexus ClearIP server for Robocall Mitigation.  ClearIP is a SIP redirect server that provides advanced Least Cost Routing (LCR), fraud control and STIR (Secure Telephony Identity Revisited) / SHAKEN (Secure Handling of Asserted information using toKENs) features. <br/>
This document provides instructions on how to configure ProSBC to operate with the TransNexus ClearIP server for Robocall Mitigation.  ClearIP is a SIP redirect server that provides advanced Least Cost Routing (LCR), fraud control and STIR (Secure Telephony Identity Revisited) / SHAKEN (Secure Handling of Asserted information using toKENs) features. <br/>


ProSBC 3.0.90 or a later version is needed to support secure caller ID using STIR/SHAKEN.
ProSBC 3.0.90 or a later version is needed to support Robocall Mitigation with TransNexus.
 
*For CNAM Verification and Robocall Analytics, please check the instruction here: https://docs.telcobridges.com/tbwiki/ProSBC:CNAM_Verification_Robocall_Analytics
 
=Typical Call Scenarios=
This section provides the simplified network diagram with typical call flows.
[[Image:ClearIP Robocall Mitigation.png|800px]]
1. Source of ServiceProvider sends a call to ProSBC.
 
2. ProSBC forwards the call to ClearIP for Robocall Mitigation process
 
3. ClearIP analyzes the call for robocall mitigation and toll fraud, then sends one of the following responses to ProSBC
 
*3a.SIP 404 Not Found: No fraud is detected, not a robocall.
 
*3b.SIP 503 Service unavailable: No fraud is detected, not a robocall.
 
*4c. SIP 603 Decline: Fraud is detected, block the call.
 
4. Upon receiving 404 or 503
    4a: - ProSBC returns SIP 503 (or mapping to the TDM cause code) to the Source switch to perform route advance 
    Call Source (TDM or SIP) --------Invite or SETUP or IAM ---------> ProSBC ----Invite--> ClearIP
    Call Source (TDM or SIP) <---SIP 503 or REL with 41 or 34 -------- ProSBC < ----503---- ClearIP
 
    4b: - ProSBC route advances on SIP 503 and sends call to next destination, does not return response to the Source switch 
    Call Source (TDM or SIP) ---Invite or SETUP or IAM ---> ProSBC ----Invite--> ClearIP
                                                            ProSBC < ----503---- ClearIP
                                                            ProSBC  ----Invite---Next Routes
Upon receiving 603
  4c: ProSBC returns SIP 603 (or mapping to the TDM cause code) to the Source switch, then release the call
    Call Source (TDM or SIP) -----Invite or SETUP or IAM ------> ProSBC ----Invite--> ClearIP
    Call Source (TDM or SIP) <---SIP 603 or REL with 21 -------- ProSBC < ----603---- ClearIP


=Network Diagram and Call Scenarios=
This section provides the simplified network diagram containing two telephone service providers, and the call scenarios.
[[Image:FreeSBC OSPrey Diagram.png|800px]]
# Source of ServiceProvider-A sends a call to ProSBC-A.
# ProSBC-A forwards the call to ClearIP-A, which is a SIP redirect server providing LCR, fraud control, SHAKEN AS (Authentication Service) and other features.
# ClearIP-A performs LCR, fraud control and SHAKEN AS logic, then sends one of the following responses to ProSBC-A
##SIP 404 Not Found: No fraud or SHAKEN AS error is detected, and routing information is unavailable.
##SIP 603 Decline: Fraud is detected or SHAKEN AS request fails.
##SIP 3xx Redirect: Destination information (ProSBC-B of ServiceProvider-B) and a SIP Identity header including a digitally signed token that includes the calling number (secure caller ID).
#ProSBC-A processes the response
##SIP 404 Not Found: ProSBC-A tries the next destination configured in its local routing policy.
##SIP 603 Decline: Proxies the response back to Source to block the call.
##SIP 3xx Redirect: Forwards the call to ProSBC-B with the Identity header.
#ProSBC-B forwards the call to ClearIP-B, which is a SIP redirect server providing fraud control, SHAKEN VS (Verification Service) and other features.
#ClearIP-B performs fraud control and SHAKEN VS logic, and then sends one of the following SIP responses to ProSBC-B.
##SIP 404 Not Found: No fraud or SHAKEN VS error is detected, and routing information is unavailable.
##SIP 603 Decline: Fraud is detected or SHAKEN VS request fails.
##SIP 3xx Redirect: Destination information (Destination of ServiceProvider-B) is attached.
#ProSBC-B processes the response
##SIP 404 Not Found: ProSBC-B tries the next destination configured in its local routing policy.
##SIP 603 Decline: Proxies the response back to ProSBC-A to block the call.
##SIP 3xx Redirect: Forwards the call to Destination.
Note: A variant scenario is that Destination of ServiceProvider-B is configured as the next destination in the local routing policy of ServiceProvider-B, ClearIP-B returns SIP 404 Not Found, then ProSBC-B does failover to Destination.
=ProSBC Configuration=
=ProSBC Configuration=
This section provides ProSBC configuration for the solution.
This section provides ProSBC configuration for the solution.
==Configure Routing Script==
==Configure Routing Script==
ProSBC is configured to use routing script to handle SIP 3xx Redirect response.
ProSBC is configured to use routing script to send some SIP headers to ClearIP to identify the source of the call.
:1. Enable routing script
:1. Enable routing script
  Gateway->Use script
  Gateway->Use script
:2. Load routing scripts
:2. Load routing scripts
  Gateway->Routes->Routing Script->Import Script File
  Gateway->Routes->Routing Script->Import Script File
     File->txnx_shaken.rb
     File->ClearIP_Query.rb
     ScriptType->TxNx
     ScriptType->filter
    Load on startup->unchecked
Gateway->Routes->Routing Script->Import Script File
    File->txnx_routing.rb
    ScriptType->Txnx
     Load on startup->checked
     Load on startup->checked
Gateway->Routes->Routing Script->Edit the main script:
*- Add the "require 'ClearIP_Query' unless defined?(ClearIPQuery)" statement at the top of the main script.
*- Add the "include ClearIPQuery" statement in the main routing class.
*- Add the filter "  before_filter :method => :ClearIP_query" in the main routing class.
[[:File:ClearIP_Query.zip|Click here to download CleaarIP_Query.rb (the fitler script) and Main_ClearIP.rb (just to show how the main script should look like) Routing Scripts]]
==Configure Transport Server for ClearIP NAP ==
  SIP -> Create New Transport Server
    Name->TS_TCP_5060
    Port Type->TCP
    Port->5060
    IP Interface-> Select the IP interface which can reach to ClearIP on the public network
==Configure ClearIP NAP ==
NAPs->Create New NAP
    Name->NAP_CLEARIP
    Proxy address->sip.clearip.com (FQDN of ClearIP-A)
==Configure Routes==


[[:File:Txnx_scripts.zip|Click here to download txnx_shaken.rb and txnx_routing.rb Routing Scripts]]
  You need to configure other routes after the ClearIP routes if you want ProSBC to perform route advances.
  Check the below link for the detail instruction to create static routes:
  https://docs.telcobridges.com/tbwiki/Toolpack:Creating_a_First_Call_Route_E


==Configure NAP (Network Access Point)==
  It could also combine with other Routeset routing:
ClearIP-A and ClearIP-B are configured as NAP on ProSBC-A and ProSBC-B respectively. A general SIP endpoint, NAP-ANY, is configured on both ProSBC’s.
  https://docs.telcobridges.com/tbwiki/Toolpack:Tsbc_Call_Routes_Settings_3.1#Label_Routing
* On ProSBC-A
NAPs->Create New NAP
    Name->NAP_ClearIP_A
    Proxy address->x.x.x.x (IP of ClearIP-A)
NAPs->Create New NAP
    Name->NAP_ANY
Use Proxy Address->Unchecked
* On ProSBC-B
NAPs->Create New NAP
    Name->NAP_ClearIP_B
    Proxy address->x.x.x.x (IP of ClearIP-B)
NAPs->Create New NAP
    Name->NAP_ANY
    Use Proxy Address->Unchecked
Note: To configure local routing policy with other destination NAPs, ClearIP NAPs should have the highest priority alone all destination NAPs.
==Configure NAP Column==
NAP column is used to mark ClearIP as redirect server.
Gateway->Routes->NAP Column->Create New NAP Column
    Name: server_type
    Type Attributes: NORMAL|REDIRECT
    Default: NORMAL
*Both NAP_ClearIP-A and NAP_ClearIP-B are configured with NAP column server_type REDIRECT.
*NAP_ANY are configured with NAP column server_type NORMAL.
==Configure Static Route==
A static route to NAP_ANY should be configured on both ProSBC’s to allow ProSBC to try the destination in the SIP 3xx response.
Gateway->Routes->Create New Static Route
    Name->ToEndpoints
    NAP->any
    Remapped_NAP->NAP_ANY
==Enable SIP Custom Header==
Enable SIP Custom Headers must be checked to pass SHAKEN Identity header and several other headers used by the solution.
Profiles->SIP->Enable SIP Custom Headers
==Disable Legacy Redirection Mode==
Use legacy redirection mode must be unchecked to allow ProSBC to use routing script to handle SIP 3xx response.
SIP->Editing SIP Configuration->Header Parameters->Use legacy redirection mode [uncheck]


==Configure Route Retry Action==
==Configure Route Retry Action==
Route retry action of 3xx, 404 and 603 must be configured to allow ProSBC to perform failover, fraud control and SHAKEN AS/VS request.
Route retry action of 3xx, 404 and 603 must be configured to allow ProSBC to perform failover, fraud control and SHAKEN AS/VS request.
  Profiles->Edit Reason Cause Mapping
  Profiles->Edit Reason Cause Mapping
    300 Multiple Choices->Route retry action->Process call routing
    302 Moved temporarily->Route retry action->Process call routing
     404 Not found->Route retry action->Continue call
     404 Not found->Route retry action->Continue call
    503 Service unavailable->Route retry action->Continue call
     603 Decline->Route retry action->Stop call
     603 Decline->Route retry action->Stop call
Notes:
Notes:
*The default route retry action of 404 is Stop call.
*The default route retry action of 404 is Stop call.
*The default route retry action of 603 is Continue call.
*The default route retry action of 603 is Continue call.

Latest revision as of 11:45, 23 September 2021

Introduction

This document provides instructions on how to configure ProSBC to operate with the TransNexus ClearIP server for Robocall Mitigation. ClearIP is a SIP redirect server that provides advanced Least Cost Routing (LCR), fraud control and STIR (Secure Telephony Identity Revisited) / SHAKEN (Secure Handling of Asserted information using toKENs) features.

ProSBC 3.0.90 or a later version is needed to support Robocall Mitigation with TransNexus.

Typical Call Scenarios

This section provides the simplified network diagram with typical call flows.


1. Source of ServiceProvider sends a call to ProSBC.

2. ProSBC forwards the call to ClearIP for Robocall Mitigation process

3. ClearIP analyzes the call for robocall mitigation and toll fraud, then sends one of the following responses to ProSBC

  • 3a.SIP 404 Not Found: No fraud is detected, not a robocall.
  • 3b.SIP 503 Service unavailable: No fraud is detected, not a robocall.
  • 4c. SIP 603 Decline: Fraud is detected, block the call.

4. Upon receiving 404 or 503

    4a: - ProSBC returns SIP 503 (or mapping to the TDM cause code) to the Source switch to perform route advance  
    Call Source (TDM or SIP) --------Invite or SETUP or IAM ---------> ProSBC ----Invite--> ClearIP
    Call Source (TDM or SIP) <---SIP 503 or REL with 41 or 34 -------- ProSBC < ----503---- ClearIP
    4b: - ProSBC route advances on SIP 503 and sends call to next destination, does not return response to the Source switch  
    Call Source (TDM or SIP) ---Invite or SETUP or IAM ---> ProSBC ----Invite--> ClearIP
                                                            ProSBC < ----503---- ClearIP
                                                            ProSBC  ----Invite---Next Routes

Upon receiving 603

  4c: ProSBC returns SIP 603 (or mapping to the TDM cause code) to the Source switch, then release the call 
   Call Source (TDM or SIP) -----Invite or SETUP or IAM ------> ProSBC ----Invite--> ClearIP
   Call Source (TDM or SIP) <---SIP 603 or REL with 21 -------- ProSBC < ----603---- ClearIP

ProSBC Configuration

This section provides ProSBC configuration for the solution.

Configure Routing Script

ProSBC is configured to use routing script to send some SIP headers to ClearIP to identify the source of the call.

1. Enable routing script
Gateway->Use script
2. Load routing scripts
Gateway->Routes->Routing Script->Import Script File
   File->ClearIP_Query.rb
   ScriptType->filter
   Load on startup->checked
Gateway->Routes->Routing Script->Edit the main script:
  • - Add the "require 'ClearIP_Query' unless defined?(ClearIPQuery)" statement at the top of the main script.
  • - Add the "include ClearIPQuery" statement in the main routing class.
  • - Add the filter " before_filter :method => :ClearIP_query" in the main routing class.

Click here to download CleaarIP_Query.rb (the fitler script) and Main_ClearIP.rb (just to show how the main script should look like) Routing Scripts

Configure Transport Server for ClearIP NAP

 SIP -> Create New Transport Server
    Name->TS_TCP_5060
    Port Type->TCP
    Port->5060
    IP Interface-> Select the IP interface which can reach to ClearIP on the public network

Configure ClearIP NAP

NAPs->Create New NAP
    Name->NAP_CLEARIP
    Proxy address->sip.clearip.com (FQDN of ClearIP-A)

Configure Routes

 You need to configure other routes after the ClearIP routes if you want ProSBC to perform route advances.
 Check the below link for the detail instruction to create static routes:
 https://docs.telcobridges.com/tbwiki/Toolpack:Creating_a_First_Call_Route_E
 It could also combine with other Routeset routing:
 https://docs.telcobridges.com/tbwiki/Toolpack:Tsbc_Call_Routes_Settings_3.1#Label_Routing

Configure Route Retry Action

Route retry action of 3xx, 404 and 603 must be configured to allow ProSBC to perform failover, fraud control and SHAKEN AS/VS request.

Profiles->Edit Reason Cause Mapping
    404 Not found->Route retry action->Continue call
    503 Service unavailable->Route retry action->Continue call
    603 Decline->Route retry action->Stop call

Notes:

  • The default route retry action of 404 is Stop call.
  • The default route retry action of 603 is Continue call.