Hi,
On our 3cx cloud instance, we see many failed authentications and blacklisted IPs.
I think it would be safer to only authorize authentications coming from the 3CX tunnel and, for generic devices, from our public IP address.
We already accept TCP 5060 and UDP 5060 from our public IP address...