diff --git a/conf/vanilla/autoload_configs/enum.conf.xml b/conf/vanilla/autoload_configs/enum.conf.xml index b9813efa27..a8f6f52f85 100644 --- a/conf/vanilla/autoload_configs/enum.conf.xml +++ b/conf/vanilla/autoload_configs/enum.conf.xml @@ -14,8 +14,8 @@ </settings> <routes> - <route service="E2U+SIP" regex="sip:(.*)" replace="sofia/${use_profile}/$1;transport=udp"/> - <route service="E2T+SIP" regex="sip:(.*)" replace="sofia/${use_profile}/$1;transport=tcp"/> - <!--<route service="E2U+XMPP" regex="XMPP:(.*)" replace="dingaling/$${xmpp_server_profile}/$1"/>--> + <route service="E2U+SIP" regex="sip:(.*)" replace="sofia/${use_profile}-ipv6/$1;transport=udp|sofia/${use_profile}/$1;transport=udp"/> + <route service="E2T+SIP" regex="sip:(.*)" replace="sofia/${use_profile}-ipv6/$1;transport=tcp|sofia/${use_profile}/$1;transport=tcp"/> + <route service="E2T+SIPS" regex="sip:(.*)" replace="sofia/${use_profile}-ipv6/$1;transport=tls|sofia/${use_profile}/$1;transport=tls"/> </routes> </configuration> diff --git a/conf/vanilla/vars.xml b/conf/vanilla/vars.xml index 28a6dc96fb..ff40fc7cfc 100644 --- a/conf/vanilla/vars.xml +++ b/conf/vanilla/vars.xml @@ -61,7 +61,7 @@ <X-PRE-PROCESS cmd="set" data="domain=$${local_ip_v4}"/> <X-PRE-PROCESS cmd="set" data="domain_name=$${domain}"/> <X-PRE-PROCESS cmd="set" data="hold_music=local_stream://moh"/> - <X-PRE-PROCESS cmd="set" data="use_profile=internal"/> + <X-PRE-PROCESS cmd="set" data="use_profile=external"/> <X-PRE-PROCESS cmd="set" data="rtp_sdes_suites=AEAD_AES_256_GCM_8|AEAD_AES_128_GCM_8|AES_CM_256_HMAC_SHA1_80|AES_CM_192_HMAC_SHA1_80|AES_CM_128_HMAC_SHA1_80|AES_CM_256_HMAC_SHA1_32|AES_CM_192_HMAC_SHA1_32|AES_CM_128_HMAC_SHA1_32|AES_CM_128_NULL_AUTH"/> <!-- Enable ZRTP globally you can override this on a per channel basis @@ -390,6 +390,14 @@ <!-- TLS cipher suite: default ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH + + The actual ciphers supported will change per platform. + + openssl ciphers -v 'ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH' + + Will show you what is available in your verion of openssl. + Freeswitch does not support non-Elliptic Curve Diffie Hellman key + exchange. --> <X-PRE-PROCESS cmd="set" data="sip_tls_ciphers=ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH"/>