- Joined
- Mar 31, 2020
- Messages
- 14
- Reaction score
- 3
Over the past week or so it appears that my 3CX system has become a target for someone. I am currently on 3CX Version 20.0 Update 9 (Build 995 Release - AI 1.4.48). The 3CX anti-hacking rules are kicking in and attempting to block them. In the 3CX logs it is saying the source is the Webclient / API.
The issue I am having is my 3CX system is behind a PFSense Firewall with the HAProxy add in due to us hosting a couple of websites / resources on the same public IP address. 3CX is seeing the attackers IP address as the PFSense IP Address instead of the actual external IP Address. This is causing all traffic to the web interface to be blocked. If I remote into the 3CX Host system I can remove the PFSense blacklist IP and the web interface becomes available again. I haven't done a firewall test recently but the last time I did it passed and none of the PFSensor or HAProxy settings have been changed since then.
From some of the web development I have done for our company I believe this is due to how HAProxy handles the connection. The HAProxy Front End rule for 3CX has the Use "ForwardFor" Option checked, is there anyway to configure 3CX to look for this value instead of the PFSense IP Address? Is there any other way to configure this to get it to work correct?
The issue I am having is my 3CX system is behind a PFSense Firewall with the HAProxy add in due to us hosting a couple of websites / resources on the same public IP address. 3CX is seeing the attackers IP address as the PFSense IP Address instead of the actual external IP Address. This is causing all traffic to the web interface to be blocked. If I remote into the 3CX Host system I can remove the PFSense blacklist IP and the web interface becomes available again. I haven't done a firewall test recently but the last time I did it passed and none of the PFSensor or HAProxy settings have been changed since then.
From some of the web development I have done for our company I believe this is due to how HAProxy handles the connection. The HAProxy Front End rule for 3CX has the Use "ForwardFor" Option checked, is there anyway to configure 3CX to look for this value instead of the PFSense IP Address? Is there any other way to configure this to get it to work correct?