5.2 Toll Fraud Prevention & Call Privileges

Key Takeaways

  • Toll fraud attacks target enterprise telephony systems through voicemail port breakout, unauthenticated DISA access, conference bridges, and unauthorized hairpin trunk-to-trunk transfers.

  • Forced Authorization Codes (FAC) enforce access security on Route Patterns by requiring callers to enter numeric codes with assigned authorization levels (0-255), logging code usage in Call Detail Records (CDR).

  • Client Matter Codes (CMC) collect project or departmental accounting identifiers without evaluating authorization levels, functioning exclusively as a billing allocation mechanism.

  • Class of Restriction (COR) implemented using tiered Partitions and Calling Search Spaces (CSS) strictly isolates route patterns, preventing unauthorized internal or lobby phones from dialing international or premium-rate destinations.

  • Setting the CUCM service parameter 'Block OffNet to OffNet Transfer' to True, paired with CUBE 'ip address trusted list' authentication, neutralizes external toll fraud and unauthenticated SIP INVITE injection.

Last updated: October 2026

5.2 Toll Fraud Prevention & Call Privileges

Toll fraud—the unauthorized hijacking of enterprise telecommunications infrastructure to place high-cost long-distance, international, or premium-rate calls—represents one of the most persistent security and financial threats to enterprise collaboration systems. Attackers exploit configuration oversights, default credentials, and unrestricted routing logic to generate tens of thousands of dollars in carrier toll charges in a single weekend. Securing enterprise dial plans requires layered defenses across Cisco Unified Communications Manager (CUCM) and Cisco Unified Border Elements (CUBE).


1. Common Toll Fraud Attack Vectors

Attackers target enterprise VoIP deployments using several distinct mechanisms:

  1. Voicemail Port Exploitation (DISA Breakout): Automated attendant and voicemail pilot numbers often provide Direct Inward System Access (DISA) or outcall notification features. Attackers break into voicemail boxes with default PINs (such as 1234 or matching the extension) and exploit administrative transfer options (e.g., pressing * or transfer codes) to obtain a dial tone on an internal line. From there, they dial external international numbers.
  2. Hairpin Trunk-to-Trunk Transfers: An external attacker places an inbound call over PSTN Trunk A to a corporate auto-attendant or receptionist, requests a transfer to an external number, or exploits an unauthenticated conference bridge. CUCM bridges the inbound PSTN call to an outbound PSTN call on Trunk B. The enterprise pays the toll charges for both circuits.
  3. Lobby & Public Endpoint Abuse: Telephones located in unsecured areas (lobbies, waiting rooms, conference facilities, shipping docks) configured with unrestricted Calling Search Spaces allow unauthorized visitors to dial international (011+) or premium 900/976 services.
  4. Unauthenticated SIP Trunk Ingress: Attackers scan public IP ranges and inject fraudulent SIP INVITE packets directly toward CUBE session border controllers, attempting to execute egress dial-peers without authentication.

2. Forced Authorization Codes (FAC) vs. Client Matter Codes (CMC)

CUCM provides two native mechanisms to prompt callers for numeric authorization codes during digit analysis: Forced Authorization Codes (FAC) and Client Matter Codes (CMC).

+--------------------------------------------------------------------------------+
|                             FAC vs. CMC PROCESSING                             |
|                                                                                |
|  User Dials Egress Route Pattern (e.g., 9.011!)                                |
|       |                                                                        |
|       +--> Pattern Matched: Requires Code                                      |
|       |    CUCM Plays Special Tone (Beep / Interrupted Dial Tone)              |
|       |                                                                        |
|       +--> Caller Inputs Code + #                                              |
|            |                                                                   |
|            +--- If FAC: Compare User Level vs. Route Pattern Required Level    |
|            |    - User Level >= Route Pattern Level: CALL PERMITTED            |
|            |    - User Level <  Route Pattern Level: CALL BLOCKED (Reorder)    |
|            |    - Code Logged in Call Detail Records (CDR)                     |
|            |                                                                   |
|            +--- If CMC: Check Code Against Configured CMC List                 |
|                 - NO LEVEL COMPARISON PERFORMED                                |
|                 - Code Logged in Call Detail Records (CDR) for Billing         |
|                 - CALL PERMITTED IF THE CODE EXISTS                            |
+--------------------------------------------------------------------------------+

Forced Authorization Codes (FAC)

  • Purpose: Security access control and privilege enforcement.
  • Configuration: Enabled on individual Route Patterns by checking Require Forced Authorization Code and defining a Minimum Authorization Level.
  • Authorization Levels: Scale from 0 (lowest) to 255 (highest).
    • Example: An administrator sets Local calls to Level 10, National Long Distance to Level 50, and International dialing to Level 100.
    • A sales representative assigned a FAC with Level 50 can dial domestic long-distance numbers, but if they attempt an international call, CUCM drops the call with a reorder tone because Level 50 < Level 100.
  • Accounting: The entered FAC is recorded in the CUCM Call Detail Record (CDR) database (authCodeDescription), linking every toll call directly to an authorized employee.

Client Matter Codes (CMC)

  • Purpose: Cost accounting and project/client billing allocation (common in legal, consulting, and accounting firms).
  • Configuration: Enabled on Route Patterns by checking Require Client Matter Code.
  • Operational Difference: CMC does not enforce authorization levels. The entered code must match a client matter code configured in CUCM, but every valid code is equal; CUCM does not rank codes as high or low privilege.
  • Accounting: The entered CMC is stamped into the CDR record (clientMatterCode), enabling billing applications to charge telecommunication costs back to specific clients or internal cost centers.

Architectural Comparison: FAC vs. CMC

AttributeForced Authorization Codes (FAC)Client Matter Codes (CMC)
Primary FunctionSecurity access restriction and toll fraud preventionClient billing and departmental cost accounting
Authorization CheckingCompares user level against route pattern minimumNo authorization level check performed
Privilege LevelsNumeric levels from 0 to 255None (all codes are equal)
Call Rejection LogicRejects the call if the code is invalid or its level is too lowRejects the call only if the code is not a configured CMC
CDR Logging FieldauthCodeDescriptionclientMatterCode
Typical Target DialingInternational (011+), Operator (0+), Directory AssistanceStandard PSTN calls charged to clients

3. Class of Restriction (COR) via Partitions and CSS

Class of Restriction (COR) defines the calling privileges of endpoints using CUCM's foundational Partition and Calling Search Space (CSS) architecture.

Partition and CSS Concatenation Rules

  • A Partition is a logical container holding directory numbers, translation patterns, and route patterns.
  • A Calling Search Space (CSS) is an ordered priority list of partitions that a device or line is permitted to reach.
  • Concatenation Priority: When both a Line CSS and a Device CSS are configured on a phone, CUCM searches the Line CSS partitions first, followed by the Device CSS partitions. The first matching partition with the closest pattern match wins.

Designing Tiered Enterprise Privileges

To enforce strict Class of Restriction, administrators establish hierarchical partitions and CSS assignments:

+--------------------------------------------------------------------------------+
|                            TIERED CALLING PRIVILEGES                           |
|                                                                                |
|  PARTITIONS:                                                                   |
|    [Emergency_PT]       --> Contains: 911, 9.911                               |
|    [Internal_PT]        --> Contains: 1XXX, 2XXX, 3XXX (Extensions)            |
|    [Local_PT]           --> Contains: 9.[2-9]XXXXXX, 9.1[2-9]XX[2-9]XXXXXX     |
|    [LongDistance_PT]    --> Contains: 9.1[2-9]XX[2-9]XXXXXX (Domestic LD)      |
|    [International_PT]   --> Contains: 9.011.! (FAC Level 100 Required)         |
|    [Blocked_PT]         --> Contains: 9.1900XXXXXXX, 9.1976XXXXXXX (Block Call)|
|                                                                                |
|  CALLING SEARCH SPACES:                                                        |
|    CSS_Lobby            --> [Emergency_PT, Internal_PT]                        |
|    CSS_StandardUser     --> [Emergency_PT, Internal_PT, Local_PT, LD_PT]       |
|    CSS_Executive        --> [Emergency_PT, Internal_PT, Local_PT, LD_PT,       |
|                              International_PT]                                 |
+--------------------------------------------------------------------------------+

Blocking Premium & Fraudulent Numbers

To prevent toll fraud to premium 900/976 entertainment or information lines:

  1. Create explicit Route Patterns: 9.1900XXXXXXX and 9.1976XXXXXXX.
  2. In the Route Pattern configuration, set Route Option to Block this pattern.
  3. Check the Urgent Priority checkbox. This instructs CUCM digit analysis to immediately execute the block without waiting for the interdigit timeout (T.302 timer), preventing callers from bypassing filters with appended digits.

4. Off-Net to Off-Net Transfer Prevention

To neutralize hairpin attacks where external callers bounce inbound calls back out to external international circuits, CUCM provides dedicated call classification controls:

Service Parameter Configuration

  • Navigate to System > Service Parameters > Cisco CallManager.
  • Find the clusterwide parameter Block OffNet To OffNet Transfer.
  • Set Block OffNet to OffNet Transfer to True.

Call Classification Architecture

CUCM classifies every call leg as either OnNet (internal, trusted) or OffNet (external, PSTN, untrusted):

  • Route patterns, gateways, and SIP trunks specify a Call Classification (OnNet or OffNet; gateways and trunks can also follow the system default).
  • Inbound calls arriving from PSTN PRI gateways or carrier SIP trunks are automatically stamped as OffNet.
  • When Block OffNet to OffNet Transfer is True, CUCM checks every transfer: if both legs are OffNet, the transfer is blocked. Forwarding to external numbers is controlled separately, through the forwarding CSS on each line.

5. CUBE Toll Fraud Prevention CLI Configuration

On Cisco IOS XE routers acting as Cisco Unified Border Elements (CUBE), toll fraud prevention is enabled by default to prevent rogue SIP signaling injection.

Default Security Behavior

By default, Cisco IOS XE inspects the source IPv4/IPv6 address of all incoming SIP INVITE requests. If the source address does not match an entry in the IP address trusted list or the session target of a configured VoIP dial peer, CUBE rejects the call with cause 21 (call rejected), which the SIP peer sees as 403 Forbidden. show ip address trusted list displays both the configured entries and the addresses learned from dial-peer session targets.

CLI Configuration Syntax

! Enable VoIP border element and toll fraud checking
voice service voip
 mode border-element
 allow-connections sip to sip
 ip address trusted authenticate
 ip address trusted list
  ipv4 198.51.100.10 255.255.255.255   ! Carrier ITSP Primary SBC
  ipv4 198.51.100.11 255.255.255.255   ! Carrier ITSP Secondary SBC
  ipv4 10.10.20.1 255.255.255.255      ! CUCM Publisher Node
  ipv4 10.10.20.2 255.255.255.255      ! CUCM Subscriber 1 Node
  ipv4 10.10.20.3 255.255.255.255      ! CUCM Subscriber 2 Node
!
! Restrict incoming SIP signaling to trusted interfaces
sip
 bind control source-interface GigabitEthernet0/0/0
 bind media source-interface GigabitEthernet0/0/0
!
! Dial-peer configuration with explicit session target
dial-peer voice 100 voip
 description Inbound / Outbound SIP Trunk to Carrier
 destination-pattern 011T
 session protocol sipv2
 session target ipv4:198.51.100.10
 incoming called-number .
 dtmf-relay rtp-nte
 codec g711ulaw
 no vad

If administrators temporarily need to disable this security feature during lab diagnostics (never recommended in production), the command is no ip address trusted authenticate under voice service voip.

Loading diagram...
Toll Fraud Defense Matrix Across Ingress CUBE and CUCM
Test Your Knowledge

What is the fundamental operational difference between Forced Authorization Codes (FAC) and Client Matter Codes (CMC) when configured on CUCM Route Patterns?

A

FAC checks the code's authorization level (0 to 255) before allowing the call; CMC only records a billing code and never blocks calls.

B

FAC encrypts the media stream using AES-256, whereas CMC routes calls unencrypted across the PSTN.

C

FAC can only be used on SIP trunks, whereas CMC can only be used on analog FXO ports of a voice gateway.

D

CMC evaluates an authorization level between 0 and 255 for each code, whereas FAC accepts any numeric string the caller enters without validation.

Test Your Knowledge

An enterprise discovers that external callers dialing into an automated attendant are manipulating transfer options to hair-pin outbound calls across corporate PSTN trunks to international destinations. Which CUCM configuration setting provides the most direct, cluster-wide protection against this toll fraud attack?

A

Change the default SIP trunk port from 5060 to 5061 without enabling TLS.

B

Assign all external gateways and PSTN trunks to the default Hub_None location.

C

Disable Cisco Discovery Protocol (CDP) on all branch switch access ports.

D

Set the cluster-wide Service Parameter 'Block OffNet to OffNet Transfer' to True.

Test Your Knowledge

A collaboration engineer is deploying a Cisco Unified Border Element (CUBE) on an ISR 4451 router running Cisco IOS XE. Incoming SIP calls from a newly provisioned SIP trunk carrier are failing with a 'SIP 403 Forbidden' response. What is the root cause of this failure under default Cisco IOS XE security policies?

A

The SIP trunk carrier is sending RTP media over UDP ports outside the default CUBE media range of 16384 to 32766, so the INVITE is refused.

B

The CUCM publisher node's Informix database is locked in read-only maintenance mode during the cutover.

C

IOS XE toll-fraud prevention is on by default, and the carrier's source IP is neither a session target nor in the ip address trusted list.

D

The CUBE router does not have DSP transcoding resources configured for G.711 to G.729 conversion.

Sections you finish are checked off in the contents.