5.2 Toll Fraud Prevention & Call Privileges
Key Takeaways
Toll fraud attacks target enterprise telephony systems through voicemail port breakout, unauthenticated DISA access, conference bridges, and unauthorized hairpin trunk-to-trunk transfers.
Forced Authorization Codes (FAC) enforce access security on Route Patterns by requiring callers to enter numeric codes with assigned authorization levels (0-255), logging code usage in Call Detail Records (CDR).
Client Matter Codes (CMC) collect project or departmental accounting identifiers without evaluating authorization levels, functioning exclusively as a billing allocation mechanism.
Class of Restriction (COR) implemented using tiered Partitions and Calling Search Spaces (CSS) strictly isolates route patterns, preventing unauthorized internal or lobby phones from dialing international or premium-rate destinations.
Setting the CUCM service parameter 'Block OffNet to OffNet Transfer' to True, paired with CUBE 'ip address trusted list' authentication, neutralizes external toll fraud and unauthenticated SIP INVITE injection.
5.2 Toll Fraud Prevention & Call Privileges
Toll fraud—the unauthorized hijacking of enterprise telecommunications infrastructure to place high-cost long-distance, international, or premium-rate calls—represents one of the most persistent security and financial threats to enterprise collaboration systems. Attackers exploit configuration oversights, default credentials, and unrestricted routing logic to generate tens of thousands of dollars in carrier toll charges in a single weekend. Securing enterprise dial plans requires layered defenses across Cisco Unified Communications Manager (CUCM) and Cisco Unified Border Elements (CUBE).
1. Common Toll Fraud Attack Vectors
Attackers target enterprise VoIP deployments using several distinct mechanisms:
- Voicemail Port Exploitation (DISA Breakout): Automated attendant and voicemail pilot numbers often provide Direct Inward System Access (DISA) or outcall notification features. Attackers break into voicemail boxes with default PINs (such as
1234or matching the extension) and exploit administrative transfer options (e.g., pressing*or transfer codes) to obtain a dial tone on an internal line. From there, they dial external international numbers. - Hairpin Trunk-to-Trunk Transfers: An external attacker places an inbound call over PSTN Trunk A to a corporate auto-attendant or receptionist, requests a transfer to an external number, or exploits an unauthenticated conference bridge. CUCM bridges the inbound PSTN call to an outbound PSTN call on Trunk B. The enterprise pays the toll charges for both circuits.
- Lobby & Public Endpoint Abuse: Telephones located in unsecured areas (lobbies, waiting rooms, conference facilities, shipping docks) configured with unrestricted Calling Search Spaces allow unauthorized visitors to dial international (
011+) or premium 900/976 services. - Unauthenticated SIP Trunk Ingress: Attackers scan public IP ranges and inject fraudulent SIP
INVITEpackets directly toward CUBE session border controllers, attempting to execute egress dial-peers without authentication.
2. Forced Authorization Codes (FAC) vs. Client Matter Codes (CMC)
CUCM provides two native mechanisms to prompt callers for numeric authorization codes during digit analysis: Forced Authorization Codes (FAC) and Client Matter Codes (CMC).
+--------------------------------------------------------------------------------+
| FAC vs. CMC PROCESSING |
| |
| User Dials Egress Route Pattern (e.g., 9.011!) |
| | |
| +--> Pattern Matched: Requires Code |
| | CUCM Plays Special Tone (Beep / Interrupted Dial Tone) |
| | |
| +--> Caller Inputs Code + # |
| | |
| +--- If FAC: Compare User Level vs. Route Pattern Required Level |
| | - User Level >= Route Pattern Level: CALL PERMITTED |
| | - User Level < Route Pattern Level: CALL BLOCKED (Reorder) |
| | - Code Logged in Call Detail Records (CDR) |
| | |
| +--- If CMC: Check Code Against Configured CMC List |
| - NO LEVEL COMPARISON PERFORMED |
| - Code Logged in Call Detail Records (CDR) for Billing |
| - CALL PERMITTED IF THE CODE EXISTS |
+--------------------------------------------------------------------------------+
Forced Authorization Codes (FAC)
- Purpose: Security access control and privilege enforcement.
- Configuration: Enabled on individual Route Patterns by checking Require Forced Authorization Code and defining a Minimum Authorization Level.
- Authorization Levels: Scale from 0 (lowest) to 255 (highest).
- Example: An administrator sets Local calls to Level 10, National Long Distance to Level 50, and International dialing to Level 100.
- A sales representative assigned a FAC with Level 50 can dial domestic long-distance numbers, but if they attempt an international call, CUCM drops the call with a reorder tone because Level 50 < Level 100.
- Accounting: The entered FAC is recorded in the CUCM Call Detail Record (CDR) database (
authCodeDescription), linking every toll call directly to an authorized employee.
Client Matter Codes (CMC)
- Purpose: Cost accounting and project/client billing allocation (common in legal, consulting, and accounting firms).
- Configuration: Enabled on Route Patterns by checking Require Client Matter Code.
- Operational Difference: CMC does not enforce authorization levels. The entered code must match a client matter code configured in CUCM, but every valid code is equal; CUCM does not rank codes as high or low privilege.
- Accounting: The entered CMC is stamped into the CDR record (
clientMatterCode), enabling billing applications to charge telecommunication costs back to specific clients or internal cost centers.
Architectural Comparison: FAC vs. CMC
| Attribute | Forced Authorization Codes (FAC) | Client Matter Codes (CMC) |
|---|---|---|
| Primary Function | Security access restriction and toll fraud prevention | Client billing and departmental cost accounting |
| Authorization Checking | Compares user level against route pattern minimum | No authorization level check performed |
| Privilege Levels | Numeric levels from 0 to 255 | None (all codes are equal) |
| Call Rejection Logic | Rejects the call if the code is invalid or its level is too low | Rejects the call only if the code is not a configured CMC |
| CDR Logging Field | authCodeDescription | clientMatterCode |
| Typical Target Dialing | International (011+), Operator (0+), Directory Assistance | Standard PSTN calls charged to clients |
3. Class of Restriction (COR) via Partitions and CSS
Class of Restriction (COR) defines the calling privileges of endpoints using CUCM's foundational Partition and Calling Search Space (CSS) architecture.
Partition and CSS Concatenation Rules
- A Partition is a logical container holding directory numbers, translation patterns, and route patterns.
- A Calling Search Space (CSS) is an ordered priority list of partitions that a device or line is permitted to reach.
- Concatenation Priority: When both a Line CSS and a Device CSS are configured on a phone, CUCM searches the Line CSS partitions first, followed by the Device CSS partitions. The first matching partition with the closest pattern match wins.
Designing Tiered Enterprise Privileges
To enforce strict Class of Restriction, administrators establish hierarchical partitions and CSS assignments:
+--------------------------------------------------------------------------------+
| TIERED CALLING PRIVILEGES |
| |
| PARTITIONS: |
| [Emergency_PT] --> Contains: 911, 9.911 |
| [Internal_PT] --> Contains: 1XXX, 2XXX, 3XXX (Extensions) |
| [Local_PT] --> Contains: 9.[2-9]XXXXXX, 9.1[2-9]XX[2-9]XXXXXX |
| [LongDistance_PT] --> Contains: 9.1[2-9]XX[2-9]XXXXXX (Domestic LD) |
| [International_PT] --> Contains: 9.011.! (FAC Level 100 Required) |
| [Blocked_PT] --> Contains: 9.1900XXXXXXX, 9.1976XXXXXXX (Block Call)|
| |
| CALLING SEARCH SPACES: |
| CSS_Lobby --> [Emergency_PT, Internal_PT] |
| CSS_StandardUser --> [Emergency_PT, Internal_PT, Local_PT, LD_PT] |
| CSS_Executive --> [Emergency_PT, Internal_PT, Local_PT, LD_PT, |
| International_PT] |
+--------------------------------------------------------------------------------+
Blocking Premium & Fraudulent Numbers
To prevent toll fraud to premium 900/976 entertainment or information lines:
- Create explicit Route Patterns:
9.1900XXXXXXXand9.1976XXXXXXX. - In the Route Pattern configuration, set Route Option to Block this pattern.
- Check the Urgent Priority checkbox. This instructs CUCM digit analysis to immediately execute the block without waiting for the interdigit timeout (T.302 timer), preventing callers from bypassing filters with appended digits.
4. Off-Net to Off-Net Transfer Prevention
To neutralize hairpin attacks where external callers bounce inbound calls back out to external international circuits, CUCM provides dedicated call classification controls:
Service Parameter Configuration
- Navigate to System > Service Parameters > Cisco CallManager.
- Find the clusterwide parameter Block OffNet To OffNet Transfer.
- Set Block OffNet to OffNet Transfer to True.
Call Classification Architecture
CUCM classifies every call leg as either OnNet (internal, trusted) or OffNet (external, PSTN, untrusted):
- Route patterns, gateways, and SIP trunks specify a Call Classification (
OnNetorOffNet; gateways and trunks can also follow the system default). - Inbound calls arriving from PSTN PRI gateways or carrier SIP trunks are automatically stamped as OffNet.
- When Block OffNet to OffNet Transfer is
True, CUCM checks every transfer: if both legs are OffNet, the transfer is blocked. Forwarding to external numbers is controlled separately, through the forwarding CSS on each line.
5. CUBE Toll Fraud Prevention CLI Configuration
On Cisco IOS XE routers acting as Cisco Unified Border Elements (CUBE), toll fraud prevention is enabled by default to prevent rogue SIP signaling injection.
Default Security Behavior
By default, Cisco IOS XE inspects the source IPv4/IPv6 address of all incoming SIP INVITE requests. If the source address does not match an entry in the IP address trusted list or the session target of a configured VoIP dial peer, CUBE rejects the call with cause 21 (call rejected), which the SIP peer sees as 403 Forbidden. show ip address trusted list displays both the configured entries and the addresses learned from dial-peer session targets.
CLI Configuration Syntax
! Enable VoIP border element and toll fraud checking
voice service voip
mode border-element
allow-connections sip to sip
ip address trusted authenticate
ip address trusted list
ipv4 198.51.100.10 255.255.255.255 ! Carrier ITSP Primary SBC
ipv4 198.51.100.11 255.255.255.255 ! Carrier ITSP Secondary SBC
ipv4 10.10.20.1 255.255.255.255 ! CUCM Publisher Node
ipv4 10.10.20.2 255.255.255.255 ! CUCM Subscriber 1 Node
ipv4 10.10.20.3 255.255.255.255 ! CUCM Subscriber 2 Node
!
! Restrict incoming SIP signaling to trusted interfaces
sip
bind control source-interface GigabitEthernet0/0/0
bind media source-interface GigabitEthernet0/0/0
!
! Dial-peer configuration with explicit session target
dial-peer voice 100 voip
description Inbound / Outbound SIP Trunk to Carrier
destination-pattern 011T
session protocol sipv2
session target ipv4:198.51.100.10
incoming called-number .
dtmf-relay rtp-nte
codec g711ulaw
no vad
If administrators temporarily need to disable this security feature during lab diagnostics (never recommended in production), the command is no ip address trusted authenticate under voice service voip.
What is the fundamental operational difference between Forced Authorization Codes (FAC) and Client Matter Codes (CMC) when configured on CUCM Route Patterns?
FAC checks the code's authorization level (0 to 255) before allowing the call; CMC only records a billing code and never blocks calls.
FAC encrypts the media stream using AES-256, whereas CMC routes calls unencrypted across the PSTN.
FAC can only be used on SIP trunks, whereas CMC can only be used on analog FXO ports of a voice gateway.
CMC evaluates an authorization level between 0 and 255 for each code, whereas FAC accepts any numeric string the caller enters without validation.
An enterprise discovers that external callers dialing into an automated attendant are manipulating transfer options to hair-pin outbound calls across corporate PSTN trunks to international destinations. Which CUCM configuration setting provides the most direct, cluster-wide protection against this toll fraud attack?
Change the default SIP trunk port from 5060 to 5061 without enabling TLS.
Assign all external gateways and PSTN trunks to the default Hub_None location.
Disable Cisco Discovery Protocol (CDP) on all branch switch access ports.
Set the cluster-wide Service Parameter 'Block OffNet to OffNet Transfer' to True.
A collaboration engineer is deploying a Cisco Unified Border Element (CUBE) on an ISR 4451 router running Cisco IOS XE. Incoming SIP calls from a newly provisioned SIP trunk carrier are failing with a 'SIP 403 Forbidden' response. What is the root cause of this failure under default Cisco IOS XE security policies?
The SIP trunk carrier is sending RTP media over UDP ports outside the default CUBE media range of 16384 to 32766, so the INVITE is refused.
The CUCM publisher node's Informix database is locked in read-only maintenance mode during the cutover.
IOS XE toll-fraud prevention is on by default, and the carrier's source IP is neither a session target nor in the ip address trusted list.
The CUBE router does not have DSP transcoding resources configured for G.711 to G.729 conversion.
Sections you finish are checked off in the contents.