[3CX App] - Firewall rules

Status
Not open for further replies.

Fabio Bologna

Free User
Joined
Apr 27, 2018
Messages
29
Reaction score
1
Goodmrning guys,
I have a slight problem I need to figure out...
I have everything working with my 3CX instance (15.5) even stuff that I genuinelly thought not possible...
We have the need to configure our firewall to protect against access to the PBX and I'm not sure on how to propperly do it... I have all the correct ports open but I see on the IP blacklist that some people are indeed trying to breach in... When I see them I just block off the entire IP range but I don't wanna be there babysitting it all the time... I wanna be able to put some kind of protection on ports 5001 5060 5061 5090 etc to avoid this sort of things but still be able to use the 3cx client app when I'm out and about... I would really like to avoid having to insert all the mac addresses of all the cell phones in the company in the firewall (Juniper SSG140 btw)...
Do you guys have an idea or can you tell me if and how did you solve this problem?

Thanks a lot for your time

Fabio
 
Hello @Fabio Bologna

Please note that although the in build security module of 3CX is very capable it cannot replace your firewall. What you can do is block all traffic on port 5060-5061 except from the IP of the provider and any remote sites that might be using STUN provisioned phones. If you are using 3CX clients you will need port 5090 and 5001 open so you can connect from anywhere.
Make sure that you are using strop passwords for your extensions and you should have no problems.
https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/
 
Hello @Fabio Bologna

Please note that although the in build security module of 3CX is very capable it cannot replace your firewall. What you can do is block all traffic on port 5060-5061 except from the IP of the provider and any remote sites that might be using STUN provisioned phones. If you are using 3CX clients you will need port 5090 and 5001 open so you can connect from anywhere.
Make sure that you are using strop passwords for your extensions and you should have no problems.
https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/

Hi YiannisH and thank you for the answer! I know it cannot replace my firewall and that is exactly why I'm here looking for solutions...
The 3CX PBX system receives/sends calls via two medias:

1. Via a PATTON 4552 on an ISDN line;
2. Via a VOIP service called Cheapnet.

The second is the only one that goes through our firewall ergo the only one I need to bloack and I already figured out how to do it because I just have to allow traffic just from that ip.

The thing about clients in your answer I really could not understand sorry but I'm fairly new to this sort of things... and our firewall/gateway thing is not the most user friendly either :confused:
 
3Cx clients that are not in the same LAN as the PBX will connect through the 3CX tunnel. The tunnel uses port 5090 so if you are using 3CX clients that connect remotely to the PBX will need to have port 5090 open so that the clients can connect.
 
3Cx clients that are not in the same LAN as the PBX will connect through the 3CX tunnel. The tunnel uses port 5090 so if you are using 3CX clients that connect remotely to the PBX will need to have port 5090 open so that the clients can connect.
Oooooh ok then let me try and set that up you are super helpful :D
 
Oooooh ok then let me try and set that up you are super helpful :D

Ok so in my firewall I have any->myethernetgroup on port 5090 open...
Client keeps saying "registration..." and stops there...
 
Navigate to the extension settings / Phone provisioning and select the 3CX client from the drop down menu. Then make sure that the option "Use 3CX Tunnel for remote connections (3CX Client only)" is enabled. If it is not enable it and send a new welcome email to reprovision the client.
 
Navigate to the extension settings / Phone provisioning and select the 3CX client from the drop down menu. Then make sure that the option "Use 3CX Tunnel for remote connections (3CX Client only)" is enabled. If it is not enable it and send a new welcome email to reprovision the client.

Option is enabled in the provisioning screen... Sure I don't have to have other ports open? just 5090??
 
5090 is used for registering remote clients to the PBX. Port 5001 is also used but for presence. To register a client remotely you only need port 5090 correctly forwarded.
 
5090 is used for registering remote clients to the PBX. Port 5001 is also used but for presence. To register a client remotely you only need port 5090 correctly forwarded.

Ok so I turned on 5001 and now it's working... are 5090 and 5001 susceptible to attacks? is there a safe way to protect them?
 
5090 is the tunnel port which is protected by the tunnel password so it is pretty safe. If you are using 3CX clients on mobile devices where static IPs are not an option then the port needs to remain open. Port 5001 is the https port that is used for management console access and presence.
 
Status
Not open for further replies.

Forum statistics

Threads
111,889
Messages
589,574
Members
164,754
Latest member
Louzan