Onyx VoiceDocumentation
All chapters

Docs / Security

Call limits (toll fraud)

Toll fraud is someone running up your carrier bill: a stolen SIP password, a hacked voicemail forward, a phone left open to the internet, used to call premium numbers or far-away countries, often many calls at once and at night. The Call limits page stops that per tenant: who may call abroad and to which countries, whether premium-rate numbers are allowed, how many outside calls may run at once, and limits on calls per hour and spending per day that stop the tenant's outside calls when crossed. Emergency calls always go through.

The Call limits page is for system administrators. Tenant administrators do not see it.

What the limits apply to

The limits apply to outside calls: every call that leaves through an outbound route to a trunk. That includes calls dialled on a phone and calls the server sends out on someone's behalf, such as a call forwarded to a mobile number or a ring group member outside the company. Internal calls between extensions are never limited.

Calls through an outbound route marked as an emergency route are never refused, whatever the limits say and even while a tenant's outside calls are stopped. See Phone numbers and routes for emergency routes.

The number checked is the number the outbound route sends: the route's prefix removed and anything it prepends added, before the trunk's own number format.

The defaults for a new tenant

A tenant whose limits nobody has changed has:

LimitDefault
International callsNobody
Allow premium-rate numbers (1-900, 1-976)Off
Outside calls at once0 (no limit)
Outside calls per hour0 (no limit)
Daily spend capNone

So out of the box nobody can call abroad, the Caribbean or premium numbers. Allow it for the tenants that need it.

Setting a tenant's limits

  1. Open Call limits. Each tenant has its own card, with the tenant's code, the outside calls in the last hour and what outside calls cost today.
  2. In the tenant's card, set the fields described below.
  3. Select Save in that card.

The engine applies the new limits within a second. From a shell, onyx toll set does the same (see the end of this chapter).

International calls

International calls has three choices:

  • Nobody: every international call is refused.
  • Only some extensions: only the extensions you list in Extensions allowed abroad may call abroad. Type the extension numbers separated by spaces, for example 101 102. Each must be a person's extension in this tenant.
  • Everybody: every extension may call abroad.

With Only some extensions, a call forwarded abroad is refused, because a forwarded call has no extension that placed it. Use Everybody if someone's calls must be forwarded to an international number.

Countries allowed narrows international calls down to some countries. Type country codes separated by spaces, for example 44 49 for the United Kingdom and Germany. Leave it empty to allow any country. A code may be longer than the country code itself, to allow only part of a country.

What counts as international

Onyx Voice treats a number as international when it is dialled:

  • with 011 in front (the North American international prefix), for example 011 44 20 7946 0000;
  • with 00 in front and more than six digits in all, as in most of the world;
  • with + in front, followed by a country code other than 1.

It also treats Caribbean and other look-alike +1 numbers as international. They are dialled like a call within North America (1 and ten digits) but are billed as international calls, and they are the classic "one ring, call me back" scam destinations. These area codes count as international: 242, 246, 264, 268, 284, 345, 441, 473, 649, 658, 664, 721, 758, 767, 784, 809, 829, 849, 868, 869 and 876. Canada and the US territories are domestic.

To allow one of them in Countries allowed, type 1 and its area code, for example 1876 for Jamaica.

Premium-rate numbers

North American pay-per-call numbers, area codes 900 and 976, are refused unless Allow premium-rate numbers (1-900, 1-976) is ticked.

Outside calls at once

Outside calls at once caps how many outside calls the tenant may have at the same time. When the limit is reached, the next outside call is refused (Too many calls at once in the refused-call log) and the caller hears that all circuits are busy. Calls in progress are not touched. 0 means no limit; the highest value is 10000.

This is a good first defence: a business with 20 people rarely needs more than a handful of outside calls at once, while fraud usually opens dozens.

Outside calls per hour and the daily spend cap

These two limits work differently. Once a minute the server checks each tenant:

  • Outside calls per hour: how many outside calls started in the last 60 minutes. When the count reaches the limit, the tenant's outside calls are stopped. 0 means no limit; the highest value is 100000.
  • Daily spend cap: what the tenant's outside calls have cost since midnight in the tenant's own time zone. When the cost reaches the cap, the tenant's outside calls are stopped. Leave it empty for no cap.

Both are counted from the call history, so a call counts once it has ended. The cost comes from the tenant's rate plan: without a rate plan, outside calls cost nothing as far as Onyx Voice knows, and the spend cap can never trip. See Billing.

When a limit trips

When Outside calls per hour or Daily spend cap is crossed, or an administrator selects Stop outside calls:

  • Every new outside call of the tenant is refused, with Calls stopped in the refused-call log. Callers hear that the number is not in service.
  • Calls already in progress continue.
  • Emergency calls still go through.
  • Internal calls and incoming calls work as before.
  • The Call limits page shows a red notice for the tenant with the reason and when it happened, and the tenant's card shows Stopped.
  • If alerts are set up, an e-mail goes out (see below).

The tenant stays stopped until an administrator lifts it. A stop does not lift itself at the next hour or at midnight.

Lifting a stop

  1. First look at the tenant's calls under Call history: international numbers, premium numbers, many short calls, calls at night. If they are fraud, change the SIP password of the device they came from (New password on the extension's page) before going further.
  2. On Call limits, select Lift the block in the tenant's red notice, then confirm with Checked the call history? Lift it.

Outside calls work again at once.

The checks keep running after you lift a stop. If the tenant is still over its limit, for example today's spend is still above the cap, the outside calls are stopped again within a minute. Raise the limit first, or wait until the last hour's calls or today's spending fall under it.

Stopping a tenant's outside calls by hand

To stop a tenant's outside calls yourself, for example while you look into a suspicious bill, select Stop outside calls in its card and confirm with Stop them now?. It takes effect at once, with the reason "Stopped by an administrator". Lift it the same way as above.

What callers hear when a call is refused

The caller hears a recorded announcement and then a fast busy tone; the call never reaches the carrier:

WhyAnnouncement
International or premium number not allowedThe call cannot be completed as dialled.
Too many outside calls at onceAll circuits are busy.
The tenant's outside calls are stoppedThe number is not in service.

The refused-call log

The Refused calls table at the bottom of the Call limits page lists the latest 100 outside calls the limits stopped, across all tenants:

ColumnWhat it shows
WhenHow long ago.
TenantThe tenant's code.
FromThe extension that dialled, or forwarded call.
NumberThe number dialled.
WhyInternational, Premium-rate number, Too many calls at once or Calls stopped.

Refused calls are kept for 90 days. A refused call is also written to the engine log, which you can read under Server › Logs & diagnostics (log Engine (calls, phones, trunks), search for refused).

A run of refused international calls from one extension in the middle of the night is the typical sign of a stolen SIP password.

Alert e-mail

To get an e-mail when a limit stops a tenant's outside calls:

  1. Make sure the server can send e-mail: the Voicemail e-mail settings under Server settings (the same mail server sends voicemail to e-mail). Test it from a shell with onyx mail test [email protected].
  2. On Call limits, in the Alerts card, type one or more addresses in Send alerts to, separated by commas, for example [email protected], [email protected].
  3. Select Save.

The e-mail has the subject "Outside calls stopped for" the tenant, says why, reminds you that emergency numbers still work, and tells you how to lift the stop. It is sent when the per-hour limit or the spend cap stops a tenant. Stopping a tenant by hand sends no e-mail. The setting is security.alert_email.

From the command line

The onyx toll commands do the same as the page, from a shell on the server (see Command line):

onyx toll show [<tenant>]
onyx toll set <tenant> [--international blocked|allowed|extensions] [--countries "44 49"] [--extensions "101 102"]
               [--premium on|off] [--max-calls <n at once>] [--per-hour <n>] [--daily-cap <amount, 0 = none>]
onyx toll block <tenant> [--reason ..]
onyx toll unblock <tenant>
onyx toll refused [<tenant>]

blocked, extensions and allowed are Nobody, Only some extensions and Everybody. For example, to let extensions 101 and 102 of Acme Dental call the United Kingdom, with at most 4 outside calls at once and a daily cap of 50:

onyx toll set acme --international extensions --extensions "101 102" --countries "44" --max-calls 4 --daily-cap 50

onyx toll show lists each tenant's limits with the last hour's calls and today's spending, and says when a tenant's outside calls are stopped. onyx toll refused shows the latest 50 refused calls. A stop or unblock from the command line reaches the engine within a minute.