
Oracle SBC Security Guide
Appendix C: DDoS Prevention for Peering Environments
Configuration Models:
The settings outlined in this appendix apply to the following configuration models:
Policy Based Realm Bridging Model
Single SIP NAT Hosted in Trusted Network Model
Supported platforms
Configuration Parameters
The following sections will discuss those DDoS prevention parameters pertinent to the scope of this
appendix. These parameters are found in three configuration areas: Media Manager, Realm
Configuration, and SIP Interface.
DDoS Configuration Parameter Descriptions
Media Manager
The following media-manager parameters have been calculated for each configuration model.
Maximum percentage of allocated total CPU usage
for untrusted traffic (%)
Minimum percentage of allocated total CPU usage
for untrusted traffic (%)
The maximum bandwidth that the SBC can
withstand (bytes/sec)
Typically, these parameters are not applied in peering configuration as the source of peer traffic is
assumed to be trusted. However, because these parameters values are set at default ‘0’, with the purpose
of maximizing the CPU resource for trusted traffic, it is suggested to minimize these values to ‘1’ so that
to guarantee optimal performance on trusted peer traffic.
Comentarios a estos manuales