Source record · tier 2 current vendor documentation
Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-border-element/220380-cisco-guide-to-harden-cisco-unified-bord.html
- Published
- 2023-04-10
- Updated
- unknown
- Accessed
- 2026-09-23
- HTTP status
- 200
- License
- Cisco website terms of use; no-redistribution; short excerpts and locators only
Source notes citing this source
- Cisco's CUBE hardening guide warns against catch-all destination patterns such as destination-pattern .T and advises routing only known number ranges. in context
- Cisco's CUBE hardening guide recommends enabling SIP-TLS and SRTP on all call legs through CUBE. in context
- The CUBE IP trusted list is populated from dial-peer session targets, voice class server-group entries and manually configured ip address trusted list entries. in context
- By default CUBE silently discards an inbound call that fails the IP trusted list check. in context
- Cisco recommends configuring CUBE to route calls only for known phone number ranges or SIP URIs. in context
- By default CUBE trusts inbound SIP from addresses in dial-peer session targets and voice class server groups and silently discards inbound calls that fail the IP trusted-list check. in context
- Cisco's hardening guide recommends Layer 3/4 access control lists at interface entry points, applied before CUBE processes the traffic, plus the Zone-Based Firewall for inspection. in context
- Cisco's hardening guide warns against catch-all dial-peer patterns such as destination-pattern .T and recommends specific number ranges or SIP URIs instead. in context
- Cisco's hardening guide recommends turning off plain UDP and TCP SIP listening on port 5060 (no transport udp, no transport tcp) and using TLS 1.2 instead. in context
- As DoS mitigation for CUBE, Cisco's hardening guide lists a dedicated RTP port range, call admission control on calls, CPU, memory and bandwidth, and call spike detection. in context
- Cisco's hardening guide advises keeping silent discard of untrusted requests enabled and using no silent-discard untrusted only when needed. in context
- Cisco's CUBE hardening guide recommends an ip address trusted list so that only known peer IPs can place calls through CUBE. in context
- Cisco's CUBE hardening guide recommends trimming SRTP ciphers to prefer AEAD_AES_256_GCM and then AEAD_AES_128_GCM, and warns that some older Cisco or peer devices may not support AEAD ciphers. in context
Cite this source record
APA
WarmTransfer. (2023, April 10). Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-technote-220380-cube-hardening
BibTeX
@misc{warmtransfer-cisco-technote-220380-cube-hardening,
title = {Cisco Guide to Harden Cisco Unified Border Element (CUBE) Enterprise Devices},
author = {{WarmTransfer}},
year = {2023},
url = {https://warmtransfer.net/knowledge/sources/cisco-technote-220380-cube-hardening},
note = {Cisco Systems, accessed 2026-09-23}
}