Hi there, we have a HDX8000 on IP only that keeps receiving calls from firstname.lastname@example.org, email@example.com, firstname.lastname@example.org, email@example.com etc where xxx.xxx.xxx.xxx is the same IP address as the unit.
This keeps happening at about every 40 minutes or so and will drop a current connected conference.
This has been discussed in the community before on multiple occasions using different topics.
This is most likely some SIP scanner trying to find a unprotected SIP server in order to commit some toll fraud if successful.
Have a google for sip vicious or friendly scanner as this explains this.
A few more details on your end would help us to make suggestions.
Is this Endpoint on the Internet and has all ports open ?
Do you use SIP ?
If no to the above simply block port 5060.
Please ensure to provide some feedback if this reply has helped you so other users can profit from your experience.
Polycom Global Services
---------------- The title Poly Employee & Community Manager is a community setting and does not reflect my role. I am just a simple volunteer in the community like everybody else. All posts and words are my own & do not represent the views of Employer.
Notice: This community forum is not an official Poly support resource, thus responses from Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge. If you need immediate and/or official assistance please open a service ticket through your proper support channels. Please also ensure you always check the VoIP , Video Endpoint , Skype for Business , PSTN or RPM FAQ's