Re: secfilter secf_check_country($gip2(src=>cc)) always replies null

Pepelux via sr-users <[email protected]>
Newsgroups gmane.comp.voip.ser
Message-ID <CA+W_FKwTjY5apHK+qmf39_E383__rQb386_kgNnkx=CsQMWZ8A@mail.gmail.com>
Can you try something like:

                if (geoip2_match("$si", "src")) {
                        secf_check_country($gip2(src=>cc));
                        if ($? == -2) {
                                xdbg("$rm from $si blocked because
Country '$gip2(src=>cc)' is blacklisted");
                                exit;
                        }
                }


On Fri, 8 Aug 2025 at 14:46, Ben Kaufman via sr-users <
[email protected]> wrote:

> Your bigger problem is in this line:
>
> if ($avp(secfilter) == -2) {
>
> The value of $avp(secfilter) is $null because no value was ever assigned
> to it. Try this (change higlighted):
>
>
> if (geoip2_match("$si", "src")) {
>     $avp(secfilter) = secf_check_country($gip2(src=>cc));
>     if ($avp(secfilter) == -2) {
>         xlog("L_ALERT", "$rm from $si blocked because Country
> '$gip2(src=>cc)' is blacklisted");
>         exit;
>     }
> }
>
>
>
> *Kaufman*
>
> *Senior Voice Engineer *
>
>
> E: [email protected]
> 24/7 support: 888.543.2000
>
>
>
>
> [image: img]
>
> SIP.US <https://sip.us> Client Support:
> 800.566.9810
>
> SIPTRUNK <https://siptrunk.com> Client Support:
> 800.250.6510
>
> Flowroute <https://flowroute.com> Client Support:
> 855.356.9768
>
>
>
> ------------------------------
> *From:* Samuel Moya Tinoco via sr-users <[email protected]>
> *Sent:* Friday, August 8, 2025 4:39 AM
> *To:* Henning Westerholt <[email protected]>; Kamailio (SER) - Users Mailing
> List <[email protected]>
> *Cc:* Samuel Moya Tinoco <[email protected]>
> *Subject:* [SR-Users] Re: secfilter secf_check_country($gip2(src=>cc))
> always replies null
>
> *CAUTION:* This email originated from outside the organization. *Do not
> click links or open attachments* unless you recognize the sender and know
> the content is safe.
>
> Hello again Henning,
>
>
>
> Thank you for your reply.
>
> I’ve try to use secf_check_country(“$gip2(src=>cc)” but it’s still the
> same. We’ll update to a newer version and try again
>
>
>
> Thank you again for your help
>
>
>
> *Samuel Moya Tinoco*
>
> Departamento de Sistemas y Redes
>
> Móvil: (+34) 606985997
>
> *[email protected] <[email protected]>*
>
>
>
> *ViveLibre*
>
> C/ La Orotava 4
>
> 28660 Boadilla del Monte
>
> Madrid
>
> *www.vivelibre.es
> <https://urldefense.com/v3/__http://www.vivelibre.es/__;!!KWzduNI!Z_HNcvt-J0_WI85yUmjeSXF7iHpA-B8UNcLzr0rB1lFXy2FXd4a42QmevjlXOY8uaK_wEwxmdpMS1v4omWlxPDo$>*
>
>
>
>
>
> Soluciones inteligentes
> para la autonomía personal
>
>
>
>
>
>
>
> *De:* Henning Westerholt <[email protected]>
> *Enviado el:* viernes, 8 de agosto de 2025 9:30
> *Para:* Kamailio (SER) - Users Mailing List <[email protected]>
> *CC:* Samuel Moya Tinoco <[email protected]>
> *Asunto:* RE: secfilter secf_check_country($gip2(src=>cc)) always replies
> null
>
>
>
> Hello,
>
>
>
> the documentation seems to have indeed some issues, the $avp(secfilter)
> seems to be not available. It should be probably fixed in the docs.
>
>
>
> Regarding your issue, I can only say that we had a similar issue with
> Kamailio 5.6.x on our customers, which apparently was solved with an update
> to a newer version. One minor thing, the docs that the command need a
> string value, so try secf_check_country(“$gip2(src=>cc)”).
>
>
>
> Cheers,
>
>
>
> Henning
>
>
>
> *From:* Samuel Moya Tinoco <*[email protected] <[email protected]>*>
> *Sent:* Freitag, 8. August 2025 08:57
> *To:* Henning Westerholt <*[email protected] <[email protected]>*>; Kamailio
> (SER) - Users Mailing List <*[email protected]
> <[email protected]>*>
> *Subject:* RE: secfilter secf_check_country($gip2(src=>cc)) always
> replies null
>
>
>
> Hello henning,
>
>
>
> Thank you for your reply.
>
> I’m using kamailio 5.6.3, when I call $gip2(src=>cc) it shows the origin
> country from the IP. I’ve test it with several countries and it works well.
>
> The problem is when I call secf_check_country($gip2(src=>cc)) that it
> replies with null.
>
>
>
> I’ve tried to insert into kamailio DDBB secfilter table exactly the output
> of $gip2(src=>cc), and I can see that it appear when using “*kamcmd
> secfilter.print country*” but it seems that the function cannot match it.
>
> Also I’ve tried to insert into the secfilter table all the spelling
> combinations of the country (both letter uppercase, both lowercase, one
> uppercase one lowercase, between quotes, etc), and the command “*kamcmd
> secfilter.print country*” shows all of them whitelisted but the function
> still replies with a null
>
>
>
> I’m not sure if there’s anything I’m doing wrong or what should I try next.
>
> Thank you again for your help
>
>
>
> *Samuel Moya Tinoco*
>
> Departamento de Sistemas y Redes
>
> Móvil: (+34) 606985997
>
> *[email protected] <[email protected]>*
>
>
>
> *ViveLibre*
>
> C/ La Orotava 4
>
> 28660 Boadilla del Monte
>
> Madrid
>
> *www.vivelibre.es
> <https://urldefense.com/v3/__https://linkprotect.cudasvc.com/url?a=http*3a*2f*2fwww.vivelibre.es*2f&c=E,1,L3SPxT1qEKzp3_Hd2xnZHrhJxIhW3z67WkP22RkW_19E33-XadjkqB2yQjNIAvIa_hgm4kBmiDCI2GeC8T4q0q9xgcu71M6fvSwWxK3PB3M,&typo=1__;JSUlJQ!!KWzduNI!Z_HNcvt-J0_WI85yUmjeSXF7iHpA-B8UNcLzr0rB1lFXy2FXd4a42QmevjlXOY8uaK_wEwxmdpMS1v4oJr90VYg$>*
>
>
>
>
>
> Soluciones inteligentes
> para la autonomía personal
>
>
>
>
>
>
>
> *De:* Henning Westerholt <*[email protected] <[email protected]>*>
> *Enviado el:* jueves, 7 de agosto de 2025 13:22
> *Para:* Kamailio (SER) - Users Mailing List <*[email protected]
> <[email protected]>*>
> *CC:* Samuel Moya Tinoco <*[email protected] <[email protected]>*>
> *Asunto:* RE: secfilter secf_check_country($gip2(src=>cc)) always replies
> null
>
>
>
> Hello,
>
>
>
> some years ago, we had a similar issue with geoip with one of our
> customers. It was not working anymore after a reload. But your problem
> looks a bit more like it’s in secfilter module.
>
>
>
> Which version of Kamailio you are using? Does it work when you call $gip2
> PV manually?
>
>
>
> Cheers,
>
>
>
> Henning
>
>
>
> *From:* Samuel Moya Tinoco via sr-users <*[email protected]
> <[email protected]>*>
> *Sent:* Donnerstag, 7. August 2025 10:08
> *To:* Kamailio (SER) - Users Mailing List <*[email protected]
> <[email protected]>*>
> *Cc:* Samuel Moya Tinoco <*[email protected] <[email protected]>*>
> *Subject:* [SR-Users] secfilter secf_check_country($gip2(src=>cc)) always
> replies null
>
>
>
> Good morning everyone,
>
>
>
> Im trying to configure secfilter module to harden our kamailio.
>
> After configuring geoip2 module and checking that using function
> geoip2_match("$si", "src") it shows the country properly. I’ve configured
> secfilter module, and I think it’s also working because kamailio service
> starts and with kamcmd secfilter.print I can see the entries from the DDBB.
>
> But when I call the function secf_check_country($gip2(src=>cc)) it always
> replies with <null> (I saw it in this variable $avp(secfilter)). I’ve also
> tried to use $? Variable and it shows “1”, in the module documentation I
> saw that 1 means “the value is not found”. But when I use kamcmd
> secfilter.print I can see the country in the output and it’s spelled
> exactly the same that in $gip2(src=>cc)
>
>
>
> I don’t know if there’s something I’m missing. Any help would be
> appreciated.
>
> Thanks in advance
>
>
>
> This is the code I’m executing
>
> if (geoip2_match("$si", "src")) {
>
>                 secf_check_country($gip2(src=>cc));
>
>                 xlog("L_ALERT", "La respuesta de de secfilter es
> $avp(secfilter)");
>
>                 xlog("L_ALERT", "$?");
>
>                 if ($avp(secfilter) == 2) {
>
>                         return;
>
>                 }
>
>         xlog("L_ALERT", "$rm from $si blocked because Country
> '$gip2(src=>cc)' is blacklisted");
>
>         exit;
>
>         }
>
> And this is what appears in the logs
>
> 2025-08-07T09:42:54.876178+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1061 a=16 n=if
>
> 2025-08-07T09:42:54.876219+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1049 a=26
> n=geoip2_match
>
> 2025-08-07T09:42:54.876252+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1051 a=32
> n=secf_check_country
>
> 2025-08-07T09:42:54.876291+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1052 a=26 n=xlog
>
> 2025-08-07T09:42:54.876473+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> ALERT: {1 1 OPTIONS *[email protected]
> <[email protected]>*} <script>: La respuesta de de
> secfilter es <null>
>
> 2025-08-07T09:42:54.876513+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1053 a=26 n=xlog
>
> 2025-08-07T09:42:54.876556+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> ALERT: {1 1 OPTIONS *[email protected]
> <[email protected]>*} <script>: 1
>
> 2025-08-07T09:42:54.876587+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1058 a=16 n=if
>
> 2025-08-07T09:42:54.876619+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1058 a=26 n=xlog
>
> 2025-08-07T09:42:54.876651+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> ALERT: {1 1 OPTIONS *[email protected]
> <[email protected]>*} <script>: OPTIONS from
> 91.228.91.69 blocked because Country 'ES' is blacklisted
>
> 2025-08-07T09:42:54.876682+02:00 PRE-KAMAILIO /usr/sbin/kamailio[1393]:
> exec: {1 1 OPTIONS *[email protected]
> <[email protected]>*} *** cfgtrace:dbg_cfg_trace():
> request_route=[GEOIP] c=[/etc/kamailio/kamailio.cfg] l=1059 a=2 n=exit
>
>
>
> The output of kamcmd secfilter.print country
>
> root@PRE-KAMAILIO:/etc/kamailio# kamcmd secfilter.print country
>
>
>
> Country
>
> =======
>
> [+] Blacklisted
>
>     -----------
>
>
>
> [+] Whitelisted
>
>     -----------
>
>     0001 -> ES
>
>
>
>
>
> *Samuel Moya Tinoco*
>
> Departamento de Sistemas y Redes
>
> Móvil: (+34) 606985997
>
> *[email protected] <[email protected]>*
>
>
>
> *ViveLibre*
>
> C/ La Orotava 4
>
> 28660 Boadilla del Monte
>
> Madrid
>
> *www.vivelibre.es
> <https://urldefense.com/v3/__https://linkprotect.cudasvc.com/url?a=http*3a*2f*2fwww.vivelibre.es*2f&c=E,1,NWBcVcZ8cyc55WJDJDgUZOcQAzfRSiI26NQtFGhFNsk_yH4VxcQUlYyabYbUg0b1y8T12x3bj9NRwZXTRdieidhV2ztX-5wnFxZ_AwIj7GGOAfo-lXkmww,,&typo=1__;JSUlJQ!!KWzduNI!Z_HNcvt-J0_WI85yUmjeSXF7iHpA-B8UNcLzr0rB1lFXy2FXd4a42QmevjlXOY8uaK_wEwxmdpMS1v4oyKzCAUA$>*
>
>
>
>
>
> Soluciones inteligentes
> para la autonomía personal
>
>
>
>
>
>
>
> *"Tanto este mensaje como todos los posibles documentos adjuntos al mismo
> son confidenciales y están dirigidos exclusivamente a los destinatarios de
> los mismos. Por favor, si Usted no es uno de dichos destinatarios,
> notifíquenos este hecho y elimine el mensaje de su sistema. Queda prohibida
> la copia, difusión o revelación de su contenido a terceros sin el previo
> consentimiento por escrito de VIVELIBRE AUTONOMÍA PERSONAL S.L.U.
> (VIVELIBRE). En caso contrario, vulnerará la legislación vigente. De
> conformidad con lo establecido en el Reglamento (UE) 2016/679, General de
> Protección de Datos, le informamos de que sus datos son objeto de
> tratamiento por VIVELIBRE, en calidad de Responsable del Tratamiento.
> VIVELIBRE tratará sus datos con la finalidad de mantener la relación
> contractual, gestionar su solicitud, así como remitirle comunicaciones de
> carácter comercial relacionadas con su ámbito de actividad y los servicios
> prestados. Si desea ejercitar sus derechos de acceso, rectificación,
> supresión, limitación, oposición o portabilidad, puede dirigirse a la
> dirección postal Calle de la Orotava 4, 28660, Boadilla del Monte, (Madrid)
> o a la dirección de correo electrónico **[email protected]
> <[email protected]>**. Para obtener más información sobre
> cómo tratamos sus datos, consulta nuestra Política de Privacidad en
> Política de Privacidad - Vivelibre.”*
>
> *"Tanto este mensaje como todos los posibles documentos adjuntos al mismo
> son confidenciales y están dirigidos exclusivamente a los destinatarios de
> los mismos. Por favor, si Usted no es uno de dichos destinatarios,
> notifíquenos este hecho y elimine el mensaje de su sistema. Queda prohibida
> la copia, difusión o revelación de su contenido a terceros sin el previo
> consentimiento por escrito de VIVELIBRE AUTONOMÍA PERSONAL S.L.U.
> (VIVELIBRE). En caso contrario, vulnerará la legislación vigente. De
> conformidad con lo establecido en el Reglamento (UE) 2016/679, General de
> Protección de Datos, le informamos de que sus datos son objeto de
> tratamiento por VIVELIBRE, en calidad de Responsable del Tratamiento.
> VIVELIBRE tratará sus datos con la finalidad de mantener la relación
> contractual, gestionar su solicitud, así como remitirle comunicaciones de
> carácter comercial relacionadas con su ámbito de actividad y los servicios
> prestados. Si desea ejercitar sus derechos de acceso, rectificación,
> supresión, limitación, oposición o portabilidad, puede dirigirse a la
> dirección postal Calle de la Orotava 4, 28660, Boadilla del Monte, (Madrid)
> o a la dirección de correo electrónico **[email protected]
> <[email protected]>**. Para obtener más información sobre
> cómo tratamos sus datos, consulta nuestra Política de Privacidad en
> Política de Privacidad - Vivelibre.”*
> *"Tanto este mensaje como todos los posibles documentos adjuntos al mismo
> son confidenciales y están dirigidos exclusivamente a los destinatarios de
> los mismos. Por favor, si Usted no es uno de dichos destinatarios,
> notifíquenos este hecho y elimine el mensaje de su sistema. Queda prohibida
> la copia, difusión o revelación de su contenido a terceros sin el previo
> consentimiento por escrito de VIVELIBRE AUTONOMÍA PERSONAL S.L.U.
> (VIVELIBRE). En caso contrario, vulnerará la legislación vigente. De
> conformidad con lo establecido en el Reglamento (UE) 2016/679, General de
> Protección de Datos, le informamos de que sus datos son objeto de
> tratamiento por VIVELIBRE, en calidad de Responsable del Tratamiento.
> VIVELIBRE tratará sus datos con la finalidad de mantener la relación
> contractual, gestionar su solicitud, así como remitirle comunicaciones de
> carácter comercial relacionadas con su ámbito de actividad y los servicios
> prestados. Si desea ejercitar sus derechos de acceso, rectificación,
> supresión, limitación, oposición o portabilidad, puede dirigirse a la
> dirección postal Calle de la Orotava 4, 28660, Boadilla del Monte, (Madrid)
> o a la dirección de correo electrónico [email protected]
> <[email protected]>. Para obtener más información sobre cómo
> tratamos sus datos, consulta nuestra Política de Privacidad en Política de
> Privacidad - Vivelibre.”*
> __________________________________________________________
> Kamailio - Users Mailing List - Non Commercial Discussions --
> [email protected]
> To unsubscribe send an email to [email protected]
> Important: keep the mailing list in the recipients, do not reply only to
> the sender!
>

__________________________________________________________
Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected]
To unsubscribe send an email to [email protected]
Important: keep the mailing list in the recipients, do not reply only to the sender!
image001.png (image/png, 3.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.