Meridian 1 Security
Meridian 1 Security
Check out Gene's "BARS 101" and details on how to stop "Transfer me to an
outside Operator" and the "90# scam" including more information about the
"extension 9000 scam" ©GHTROUT
An audit of the Meridian 1 telephone system will ensure that every possible "system"
precaution has been made to prevent fraud. The first step involves querying data
from the system in the form of printouts (or "capturing" the data to a file in a PC).
The next step is to analyze the data and confirm the reason for each entry. Please be
advised that this procedure is not designed for all "networked" Meridian 1 systems,
however, most of the items apply to all systems. Use at your own risk. ©GHTROUT
PRINTOUTS REQUIRED FOR SECURITY AUDIT: It is suggested that you "capture" all
of the data from these printouts to separate files. This can be accomplished with a PC
and communications program. For the BARS LD90 NET printout, look here
©GHTROUT
List (LST) the following FEAT entries to form an information base on the telephones.
©GHTROUT
From the printouts, a review of the following areas must be made. Some of the items
may or may not be appropriate depending on the applications of the telephone
system. ©GHTROUT
• Restrict the main numbers and DID range within the BARS
system. There is no need to call from an outgoing to an
incoming line at the same location. ©GHTROUT
TRUNKS • Confirm that all trunks have TGAR assigned. ©GHTROUT
• Confirm that all incoming and TIE trunks have class of service
SRE assigned. (caution on networked systems) ©GHTROUT
• Confirm that all trunks have an NCOS of zero. ©GHTROUT
• Voice Mail cannot connect to an outgoing line, but can receive incoming calls.
©GHTROUT
• Callers on the far end of a TIE line cannot call out through your end (for their
sake, both ends should be SRE). ©GHTROUT
• If a route access code is accessed (if there was no match between the TGAR
and TARG), the caller cannot dial 1 or 0 as the leading digits. ©GHTROUT
• If the caller makes a "dial 9" BARS call, the NCOS will control the call.
©GHTROUT
• The best restriction is to have all trunk routes TARG'd to 1 and all TNs
(including actual trunk TNs) TGAR'd to 1. This will block all access to direct
trunk route selection. ©GHTROUT
Example: You have a dedicated long The RLI is the List of Trunk Routes an
distance route at your company. You NPA, NXX or SPN can call out on.
also have a local Telco trunk route.
The cost to call Area Code 312 is In the example below, you can also refer to
cheaper over the Long Distance THIS
route. If that long distance trunk
route fails or becomes busy, you RLI 4 - The LIST in the example
would like some callers to fail over to
the local Telco route. ENTR 0 The first entry in the LIST
LTER NO
With BARS, you can program the ROUT 15 The Long Distance route in
system so the long distance route is the example
preferred for all calls to NPA 312, but TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
during a failure or all trunks busy
CNV NO
condition, the most important users
EXP NO
(or any users you specify) will FRL 3
automatically route over the local DMI 0
Telco lines. You assign NPAs to Route FCI 0
Lists. Route Lists contain the trunk FSNI 0
routes OHQ YES
CBQ YES
The column to you your left (no, the
other left...on the right) is a route list
printed out. ENTR 1 The second entry in the LIST
LTER NO
ROUT 10 The local Telco route in
the example
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP YES
FRL 3
DMI 12
FCI 0
FSNI 0
OHQ YES
CBQ YES
ISET 2
MFRL 2
Back to TOP
BARS 101 - Quick Tour of a Meridian 1 BARS Call
Click the underlined links to take you to the details and/or explanation of that
prompt.
Basic Automatic Route Selection. If you dial "9", you are accessing BARS. "9" is the
"BARS Access Code"
>ld 90
ESN000
REQ prt
CUST 0
FEAT net
TRAN ac1
TYPE npa
NPA 1312
NPA 1312 <-- This is the network number (prefix)
RLI 11 <-- This is the Route List that the prefix gets
instruction from
DENY 976 <-- This is an exchange in NPA 312 that is
blocked. Optional, but common
SDRR DENY CODES = 1
DMI 0
ITEI NONE
REQ end
Along with the trunk route and the FRL, you can apply
specific "digit manipulation" with the DMI entry. The DMI
entries are explained here.
>ld 86
ESN000
REQ prt
CUST 0
FEAT rlb
RLI 11
RLI 11
ENTR 0 <-- This is the list's first "Entry Number"
LTER NO
ROUT 15 <-- This is the first choice Trunk Route Number
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP NO
FRL 3 <-- This is the Facility Restriction Level
DMI 10 <-- This is the Digit Manipulation Index Number
FCI 0
FSNI 0
OHQ YES
CBQ YES
ENTR 1 <-- This is the list's second "Entry Number"
LTER NO
ROUT 9 <-- This is the second choice Trunk Route Number
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP YES <-- This is considered the "expensive" choice
FRL 6 <-- Note that the Facility Restriction Level is higher
DMI 0 <-- Note no digit manipulation is required for this
trunk route
FCI 0
FSNI 0
OHQ YES
CBQ YES
ISET 2
MFRL 3
REQ end
>ld 87
ESN000
REQ prt
CUST 0
FEAT nctl
NRNG 0 7 <-- Range from NCOS 0 through 7 was requested
SOHQ NO
SCBQ YES
CBTL 10
---------------
NCOS 0
EQA NO
FRL 0
RWTA NO
NSC NO
OHQ NO
CBQ NO
MPRI 0
PROM 0
---------------
NCOS 1
EQA NO
FRL 1
RWTA NO
NSC NO
OHQ NO
CBQ YES
RETT 10
RETC 5
ROUT I
RADT 0
SPRI 0
MPRI 0
PROM 0
---------------
NCOS 2
EQA NO
FRL 0
RWTA NO
NSC NO
OHQ NO
CBQ NO
MPRI 0
PROM 0
---------------
NCOS 3
EQA NO
FRL 3 <-- NCOS 3 equals FRL 3.
RWTA YES
NSC NO
OHQ NO
CBQ YES
RETT 10
RETC 5
ROUT I
RADT 10
SPRI 0
MPRI 0
PROM 0
---------------
NCOS 4
EQA NO
FRL 4
RWTA YES
NSC NO
OHQ NO
CBQ YES
RETT 10
RETC 5
ROUT A
RADT 10
SPRI 0
MPRI 0
PROM 0
---------------
NCOS 5
EQA NO
FRL 5
RWTA NO
NSC NO
OHQ NO
CBQ YES
RETT 10
RETC 5
ROUT A
RADT 10
SPRI 0
MPRI 0
PROM 0
---------------
NCOS 6
EQA NO
FRL 6 <-- NCOS 6 equals FRL 6.
RWTA NO
NSC NO
OHQ NO
CBQ YES
RETT 10
RETC 5
ROUT A
RADT 0
SPRI 0
MPRI 0
PROM 0
---------------
NCOS 7
EQA NO
FRL 7
RWTA NO
NSC NO
OHQ NO
CBQ YES
RETT 10
RETC 5
ROUT A
RADT 0
SPRI 0
MPRI 0
PROM 0
TOHQ NONE
REQ prt
CUST 0
FEAT dgt
DMI 10
DMI 10 <-- This is simply the index number.
DEL 1 <-- This says "delete the first digit after "9"
CTYP NCHG
REQ prt
CUST 0
FEAT dgt
DMI 3
DMI 3
DEL 0 <-- This says "delete nothing after 9"
INST 1010288 <-- This says "Insert 1010288 after 9 and
before the actual number dialed". 1010288 is a way to
select ATT for a call.
CTYP NCHG
REQ end
DES 5135
TN 004 0 14 00
TYPE 500
CDEN 4D
CUST 0
DN 5135 MARP
CPND
NAME Typical User
XPLN 9
DISPLAY_FMT FIRST,LAST
AST NO
IAPG 0
HUNT
TGAR 1
LDN NO
NCOS 5 <-- What FRL does this equal?
SGRP 0
RNPG 0
LNRS 16
XLST
SCI 0
CLS CTD DTN FBD XFA WTA THFD FND HTD ONS
LPR XRA CWD SWD MWA LPD XHD CCSD LNA TVD
CFTD SFD C6D PDN CNID CLBD AUTU
ICDD CDMD EHTD MCTD
GPUD DPUD CFXD ARHD OVDD AGTD CLTD LDTA ASCD
MBXD CPFA CPTA DDGA NAMA
SHL ABDD CFHD
USRD BNRD OCBD
RCO 0
PLEV 02
FTR CFW 4
DATE 28 NOV 1978
The ESN data block is the root of BARS. Before BARS can
be set up, the ESN data block must be defined.
>ld 86
ESN000
REQ prt
CUST 0
FEAT esn
MXLC 0
MXSD 30
MXIX 0
MXDM 100
MXRL 80
MXFC 60
MXFS 0
MXSC 120
NCDP 4
AC1 9 <-- This is where "9" is defined
AC2
DLTN YES
ERWT YES
ERDT 0
TODS 0 00 00 23 59 <-- This section refers only to time of
day routing controls
RTCL DIS
NCOS 0 - 0 <-- This section refers only to time of day
routing controls
NCOS 1 - 1
NCOS 2 - 2
NCOS 3 - 3
NCOS 4 - 4
NCOS 5 - 5
NCOS 6 - 6
NCOS 7 - 7
<continued to 99...>
NCOS 99 - 99
ETOD
TGAR NO
REQ end
ENTR = ENTRY IN RLI. An ENTR is just one of the entries in a a Route List
Index. Each Trunk Route specified in a Route List is defined in it's own
ENTR
EXAMPLE
ENTR 0
LTER NO
ROUT 15
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP NO
FRL 2
DMI 0
FCI 0
FSNI 0
OHQ YES
CBQ YES
ENTR 1
LTER NO
ROUT 7
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP YES
FRL 5
DMI 12
FCI 0
FSNI 0
OHQ YES
CBQ YES
ISET 2
MFRL 2
ROUT = The TRUNK ROUTE one of the ENTR's in a RLI will use for calls
ENTR 0
LTER NO
ROUT 15
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP NO
FRL 2
DMI 0
FCI 0
FSNI 0
OHQ YES
CBQ YES
ENTR 1
LTER NO
ROUT 7
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP YES
FRL 5
DMI 12
FCI 0
FSNI 0
OHQ YES
CBQ YES
ISET 2
MFRL 2
FRL = FACILITY RESTRICTION LEVEL OF ENTRY IN RLI
The basic restriction philosophy is this: Each ENTR of a Route List has an
FRL that must be met or exceeded by the telephone attempting to dial. The
telephone is assigned it's "FRL value" at the NCOS prompt. The NCOS and
the FRL are linked in the LD87 NCTL datablock
ENTR 0
LTER NO
ROUT 15
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP NO
FRL 2
DMI 0
FCI 0
FSNI 0
OHQ YES
CBQ YES
ENTR 1
LTER NO
ROUT 7
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP YES
FRL 5
DMI 12
FCI 0
FSNI 0
OHQ YES
CBQ YES
ISET 2
MFRL 2
DMI = DIGIT MANIPULATION INDEX
Create an instruction to delete or insert digits and apply it to all calls using a
RLI's Entry
Example. If a call is sent out the second ENTR below, it will go out Trunk
Route 7. Before the call is outpulsed, the digits "1010288" are inserted. An
example of someone who wants to pick ATT for the long line carrier.
DMI IN RLI
ENTR 0
LTER NO
ROUT 15
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP NO
FRL 2
DMI 0 (Not here - assume Trunk Route did not need it. Look below)
FCI 0
FSNI 0
OHQ YES
CBQ YES
ENTR 1
LTER NO
ROUT 7
TOD 0 ON 1 ON 2 ON 3 ON
4 ON 5 ON 6 ON 7 ON
CNV NO
EXP YES
FRL 5
DMI 12 <-----------------H E R E
FCI 0
FSNI 0
OHQ YES
CBQ YES
ISET 2
MFRL 2
EACH NCOS = AN FRL - DEFINED IN FRL = FACILITY RESTRICTION LEVEL
LD87 NCTL OF ENTR IN RLI
The basic restriction philosophy is this:
NCTL DATABLOCK Each ENTR of a Route List has an FRL that
must be met or exceeded by the
>LD 87 telephone. The telephone is assigned it's
ESN000 FRL value in the NCOS prompt. The NCOS
REQ PRT and the FRL are linked in the LD87 NCTL
CUST 0 datablock
FEAT NCTL
-------------- RLI ROUTE LIST
NCOS 1
EQA NO
ENTR 0
FRL 1 = VALUE OF NCOS 1
LTER NO
RWTA NO
ROUT 15
NSC NO
TOD 0 ON 1 ON 2 ON 3 ON
OHQ NO
4 ON 5 ON 6 ON 7 ON
CBQ NO
CNV NO
MPRI 0
EXP NO
PROM 0
FRL 2
--------------
DMI 0
NCOS 2
FCI 0
EQA NO
FSNI 0
FRL 2 = VALUE OF NCOS 2
OHQ YES
RWTA NO
CBQ YES
NSC NO
OHQ NO
CBQ NO
ENTR 1
MPRI 0
LTER NO
PROM 0
ROUT 7
--------------
TOD 0 ON 1 ON 2 ON 3 ON
NCOS 5
4 ON 5 ON 6 ON 7 ON
EQA NO
CNV NO
FRL 5 = VALUE OF NCOS 5
EXP YES
RWTA NO
FRL 5
NSC NO
DMI 12
OHQ NO
FCI 0
CBQ YES
FSNI 0
RETT 10
OHQ YES
RETC 5
CBQ YES
ROUT A
ISET 2
RADT 10
MFRL 2
SPRI 0
MPRI 0
PROM 0
If you want to organize records for easy reading, download this simple Excel file
that has a worksheet for each report. Also included is a "line number" column so you
can perform sorting. Not rocket science, but Excel is nice for Meridian printouts
when you create a separate sort column.