[OpenSIPS-Users] Temporarily unavailable

Prathibha B prathibhab.tvm at gmail.com
Tue Sep 26 08:10:34 UTC 2023


I've created two users and they are registered to opensips. When I try to
connect, user 1 to user 2, I get temporarily unavailable. Config file is
attached with this email.

-- 
Regards,
B.Prathibha
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opensips.org/pipermail/users/attachments/20230926/3d8dd45b/attachment.html>
-------------- next part --------------
#
# OpenSIPS residential configuration script
#     by OpenSIPS Solutions <team at opensips-solutions.com>
#
# Please refer to the Core CookBook at:
#      http://www.opensips.org/Resources/DocsCookbooks
# for a explanation of possible statements, functions and parameters.
#


####### Global Parameters #########

log_level=5
xlog_level=5
log_stderror=no
log_facility=LOG_LOCAL0

open_files_limit=4096

udp_workers=4

/* uncomment the next line to enable the auto temporary blacklisting of
   not available destinations (default disabled) */
#disable_dns_blacklist=no

/* uncomment the next line to enable IPv6 lookup after IPv4 dns
   lookup failures (default disabled) */
#dns_try_ipv6=yes


socket=udp:172.31.34.24:5060 as 65.2.167.22:5060  # CUSTOMIZE ME
socket=tcp:172.31.34.24:5060 as 65.2.167.22:5060  # CUSTOMIZE ME
socket=tls:172.31.34.24:5061 as 65.2.167.22:5061  # CUSTOMIZE ME
socket=ws:172.31.34.24:8080 as 65.2.167.22:8080
socket=wss:172.31.34.24:7443 as 65.2.167.22:7443
####### Modules Section ########

#set module path
mpath="/usr/lib/x86_64-linux-gnu/opensips/modules/"

#### SIGNALING module
loadmodule "signaling.so"

#### StateLess module
loadmodule "sl.so"

#### Transaction Module
loadmodule "tm.so"
modparam("tm", "fr_timeout", 5)
modparam("tm", "fr_inv_timeout", 30)
modparam("tm", "restart_fr_on_each_reply", 0)
modparam("tm", "onreply_avp_mode", 1)

#### Record Route Module
loadmodule "rr.so"
/* do not append from tag to the RR (no need for this script) */
modparam("rr", "append_fromtag", 0)

#### MAX ForWarD module
loadmodule "maxfwd.so"

#### SIP MSG OPerationS module
loadmodule "sipmsgops.so"

#### FIFO Management Interface
loadmodule "mi_fifo.so"
modparam("mi_fifo", "fifo_name", "/tmp/opensips_fifo")
modparam("mi_fifo", "fifo_mode", 0666)

#### MYSQL module
loadmodule "db_mysql.so"

#### HTTPD module
loadmodule "httpd.so"
modparam("httpd", "port", 8888)

#### USeR LOCation module
loadmodule "usrloc.so"
modparam("usrloc", "nat_bflag", "NAT")
modparam("usrloc", "working_mode_preset", "single-instance-sql-write-back")
modparam("usrloc", "db_url",
        "mysql://root:root@localhost/opensips") # CUSTOMIZE ME


#### REGISTRAR module
loadmodule "registrar.so"
modparam("registrar", "tcp_persistent_flag", "TCP_PERSISTENT")
modparam("registrar", "received_avp", "$avp(received_nh)")/* uncomment the next line not to allow more than 10 contacts per AOR */
#modparam("registrar", "max_contacts", 10)

#### ACCounting module
loadmodule "acc.so"
/* what special events should be accounted ? */
modparam("acc", "early_media", 0)
modparam("acc", "report_cancels", 0)
/* by default we do not adjust the direct of the sequential requests.
   if you enable this parameter, be sure to enable "append_fromtag"
   in "rr" module */
modparam("acc", "detect_direction", 0)
modparam("acc", "db_url",
        "mysql://root:root@localhost/opensips") # CUSTOMIZE ME

#### AUTHentication modules
loadmodule "auth.so"
loadmodule "auth_db.so"
modparam("auth_db", "calculate_ha1", yes)
modparam("auth_db", "password_column", "password")
modparam("auth_db", "db_url",
        "mysql://root:root@localhost/opensips") # CUSTOMIZE ME
modparam("auth_db", "load_credentials", "")

#### ALIAS module
loadmodule "alias_db.so"
modparam("alias_db", "db_url",
        "mysql://root:root@localhost/opensips") # CUSTOMIZE ME

#### DIALOG module
loadmodule "dialog.so"
modparam("dialog", "dlg_match_mode", 1)
modparam("dialog", "default_timeout", 21600)  # 6 hours timeout
modparam("dialog", "db_mode", 2)
modparam("dialog", "db_url",
        "mysql://root:root@localhost/opensips") # CUSTOMIZE ME

####  NAT modules
loadmodule "nathelper.so"
modparam("nathelper", "natping_interval", 10)
modparam("nathelper", "ping_nated_only", 1)
modparam("nathelper", "sipping_bflag", "SIP_PING_FLAG")
modparam("nathelper", "sipping_from", "sip:pinger at 127.0.0.1") #CUSTOMIZE ME
modparam("nathelper", "received_avp", "$avp(received_nh)")

loadmodule "rtpengine.so"
modparam("rtpengine", "rtpengine_sock", "udp:172.31.34.24:2225")

####  DIALPLAN module
loadmodule "dialplan.so"
modparam("dialplan", "db_url",
        "mysql://root:root@localhost/opensips") # CUSTOMIZE ME

####  MI_HTTP module
loadmodule "mi_http.so"

loadmodule "proto_udp.so"
loadmodule "proto_tcp.so"
loadmodule "proto_tls.so"
loadmodule "proto_ws.so"
loadmodule "proto_wss.so"
modparam("proto_wss", "wss_port", 7443)
modparam("proto_wss", "wss_max_msg_chunks", 16)

loadmodule "tls_openssl.so"
#loadmodule "tls_wolfssl.so"
loadmodule "tls_mgm.so"
modparam("tls_mgm","server_domain", "default")
modparam("tls_mgm","verify_cert", "[default]0")
modparam("tls_mgm","require_cert", "[default]0")
#modparam("tls_mgm","certificate", "[default]/etc/opensips/tls/rootCA/cacert.pem")
#modparam("tls_mgm","private_key", "[default]/etc/opensips/tls/rootCA/private/cakey.pem")
#modparam("tls_mgm","ca_list", "[bp3.erss.in]/etc/opensips/tls/user/user-calist.pem")
modparam("tls_mgm", "tls_method", "[default]SSLv23")
modparam("tls_mgm","tls_library","openssl")
#modparam("tls_mgm", "certificate", "[default]/etc/opensips/tls/user/caKey.pem")
#modparam("tls_mgm", "private_key", "[default]/etc/opensips/tls/user/privateKey.pem")
#modparam("tls_mgm", "client_domain", "14.139.
modparam("tls_mgm", "certificate", "[default]/home/ubuntu/cert.pem")
modparam("tls_mgm", "private_key", "[default]/home/ubuntu/privkey.pem")

####### Routing Logic ########

# main request routing logic
route{

        # initial NAT handling; detect if the request comes from behind a NAT
        # and apply contact fixing
        force_rport();
        if (nat_uac_test(23)) {
                if (is_method("REGISTER")) {
                        fix_nated_register();
                        setbflag("NAT");
                } else {
                        fix_nated_contact();
                        setflag("NAT");
                }
        }

        if (!mf_process_maxfwd_header(10)) {
                send_reply(483,"Too Many Hops");
                exit;
        }
if (has_totag()) {

                # handle hop-by-hop ACK (no routing required)
                if ( is_method("ACK") && t_check_trans() ) {
                        t_relay();
                        exit;
                }

                # sequential request within a dialog should
                # take the path determined by record-routing
                if ( !loose_route() ) {
                        # we do record-routing for all our traffic, so we should not
                        # receive any sequential requests without Route hdr.
                        send_reply(404,"Not here");
                        exit;
                }

                # validate the sequential request against dialog
                if ( $DLG_status!=NULL && !validate_dialog() ) {
                        xlog("In-Dialog $rm from $si (callid=$ci) is not valid according to dialog\n");
                        ## exit;
                }

                if (is_method("BYE")) {
                        # do accounting even if the transaction fails
                        do_accounting("db","failed");

                }


                if (check_route_param("nat=yes"))
                        setflag("NAT");
                # route it out to whatever destination was set by loose_route()
                # in $du (destination URI).
                route(relay);
                exit;
        }
# CANCEL processing
        if (is_method("CANCEL")) {
                if (t_check_trans())
                        t_relay();
                exit;
        }

        # absorb retransmissions, but do not create transaction
        t_check_trans();

        if ( !(is_method("REGISTER")  ) ) {

                if (is_myself("$fd")) {

                        # authenticate if from local subscriber
                        # authenticate all initial non-REGISTER request that pretend to be
                        # generated by local subscriber (domain from FROM URI is local)
                        if (!proxy_authorize("", "subscriber")) {
                                proxy_challenge("", "auth");
                                exit;
                        }
                        if ($au!=$fU) {
                                send_reply(403,"Forbidden auth ID");
                                exit;
                        }

                        consume_credentials();
                        # caller authenticated

                } else {
                        # if caller is not local, then called number must be local

                        if (!is_myself("$rd")) {
                                send_reply(403,"Relay Forbidden");
                                exit;
                        }
                }

        }

# preloaded route checking
        if (loose_route()) {
                xlog("L_ERR",
                        "Attempt to route with preloaded Route's [$fu/$tu/$ru/$ci]");
		if (is_method("INVITE")) {
			# even if in most of the cases is useless, do RR for
			# re-INVITEs alos, as some buggy clients do change route set
			# during the dialog.
			record_route();
		}
                exit;
        }

        # record routing
        if (!is_method("REGISTER|MESSAGE"))
                record_route();

        # account only INVITEs
        if (is_method("INVITE")) {

                # create dialog with timeout
                if ( !create_dialog("B") ) {
                        send_reply(500,"Internal Server Error");
                        exit;
                }

                do_accounting("db");

        }


        if (!is_myself("$rd")) {
                append_hf("P-hint: outbound\r\n");

                # if you have some interdomain connections via TLS
                ## CUSTOMIZE IF NEEDED
                ##if ($rd=="tls_domain1.net"
                ## || $rd=="tls_domain2.net"
                ##) {
                ##      force_send_socket("tls:127.0.0.1:5061"); # CUSTOMIZE
                ##}

                route(relay);
        }
# requests for my domain

        if (is_method("PUBLISH|SUBSCRIBE")) {
                send_reply(503, "Service Unavailable");
                exit;
        }

        if (is_method("REGISTER")) {
                # authenticate the REGISTER requests
                if (!www_authorize("", "subscriber")) {
                        www_challenge("", "auth");
                        exit;
                }

                if ($au!=$tU) {
                        send_reply(403,"Forbidden auth ID");
                        exit;
                }
                if ($socket_in(proto) == "tcp" || $socket_in(proto) == "tls")
                        setflag("TCP_PERSISTENT");
                if (isflagset("NAT")) {
                        setbflag("SIP_PING_FLAG");
                }
                # store the registration and generate a SIP reply
                if (!save("location")){
                        sl_reply_error();
                        xlog("failed to register AoR $tu\n");
                        exit;
                }

                exit;
        }

        if ($rU==NULL) {
                # request with no Username in RURI
                send_reply(484,"Address Incomplete");
                exit;
        }
# apply DB based aliases
        alias_db_lookup("dbaliases");


        # apply transformations from dialplan table
        dp_translate( 0, "$rU", $rU);

        # check if the clients are using WebSockets or WebSocketSecure
        if ($socket_in(proto) == "WS" || $socket_in(proto) == "WSS")
                setflag('SRC_WS');
        else
                setflag('SRC_SIP');


        # consider the client is behind NAT - always fix the contact
        fix_nated_contact();

        if (is_method("REGISTER")) {

                # indicate that the client supports DTLS
                # so we know when he is called
                if (isflagset('SRC_WS'))
                        setbflag('DST_WS');

                fix_nated_register();
                if (!save("location"))
                        sl_reply_error();

                exit;
        }

        # do lookup with method filtering
        if (!lookup("location","m")) {
                if (!db_does_uri_exist("$ru","subscriber")) {
                        send_reply(420,"Bad Extension");
                        exit;
                }

                t_reply(404, "Not Found");
                exit;
        }
if (isbflagset("NAT")) setflag("NAT");


        # when routing via usrloc, log the missed calls also
        do_accounting("db","missed");

        route(relay);
}
route[relay] {
	# for INVITEs enable some additional helper routes
	if (is_method("INVITE")) {
		t_on_branch("handle_nat");
		t_on_reply("handle_nat");
	} else if (is_method("BYE|CANCEL")) {
		rtpengine_delete();
	}

	if (!t_relay()) {
		send_reply(500,"Internal Error");
	};
	exit;
}

branch_route[handle_nat] {

	if (!is_method("INVITE") || !has_body("application/sdp"))
		return;

	if (isflagset('SRC_WS') && isbflagset('DST_WS'))
		$var(rtpengine_flags) = "ICE=force-relay DTLS=passive";
	else if (isflagset('SRC_WS') && !isbflagset('DST_WS'))
		$var(rtpengine_flags) = "RTP/AVP replace-session-connection replace-origin ICE=remove";
	else if (!isflagset('SRC_WS') && isbflagset('DST_WS'))
		$var(rtpengine_flags) = "UDP/TLS/RTP/SAVPF ICE=force";
	else if (!isflagset('SRC_WS') && !isbflagset('DST_WS'))
		$var(rtpengine_flags) = "RTP/AVP replace-session-connection replace-origin ICE=remove";

	rtpengine_offer("$var(rtpengine_flags)");
}

onreply_route[handle_nat] {

	fix_nated_contact();
	if (!has_body("application/sdp"))
		return;

	if (isflagset('SRC_WS') && isbflagset('DST_WS'))
		$var(rtpengine_flags) = "ICE=force-relay DTLS=passive";
	else if (isflagset('SRC_WS') && !isbflagset('DST_WS'))
		$var(rtpengine_flags) = "UDP/TLS/RTP/SAVPF ICE=force";
	else if (!isflagset('SRC_WS') && isbflagset('DST_WS'))
		$var(rtpengine_flags) = "RTP/AVP replace-session-connection replace-origin ICE=remove";
	else if (!isflagset('SRC_WS') && !isbflagset('DST_WS'))
		$var(rtpengine_flags) = "RTP/AVP replace-session-connection replace-origin ICE=remove";

	rtpengine_answer("$var(rtpengine_flags)");

}

failure_route[missed_call] {
        if (t_was_cancelled()) {
                exit;
        }

        # uncomment the following lines if you want to block client 
        # redirect based on 3xx replies.
        ##if (t_check_status("3[0-9][0-9]")) {
        ##t_reply(404,"Not found");
        ##      exit;
        ##}


}

local_route {
        if (is_method("BYE") && $DLG_dir=="UPSTREAM") {

                acc_db_request("200 Dialog Timeout", "acc");

        }
}



More information about the Users mailing list