Solved 3CX Hosted & Port 5060

Status
Not open for further replies.

FleckTeck

Customer
Advanced Certified
Joined
Jul 19, 2019
Messages
8
Reaction score
1
One of the concerns I have utilizing 3CX Hosted is the amount of junk that tries to register to my PBX, despite having set pretty strict auto-blacklist policies. Considering 3CX Hosted does not officially support STUN connections, why even have the port open and the option available? I would love to see at least the option to just turn off 5060 all together so that registration attempts are just dropped, and the bots scanning the internet for IP's that respond with 5060 as an open port just see nothing.

Any thoughts on this?
 
@FleckTeck I can understand what you are saying but for cases like this, on the Management Console >> Security >> Anti-Hacking >> Automatic Global 3CX IP Blacklist option must be enabled.
With this option enabled, PBX ignores totally any requests coming from any ip address that is listed in the Global 3CX Antihacking Defense Program and this will not consume an resources from your machine.
Having a machine hosted ( anywhere ) will be exposed, this is why we have enabled this option in the PBX side.
 
@FleckTeck I can understand what you are saying but for cases like this, on the Management Console >> Security >> Anti-Hacking >> Automatic Global 3CX IP Blacklist option must be enabled.
With this option enabled, PBX ignores totally any requests coming from any ip address that is listed in the Global 3CX Antihacking Defense Program and this will not consume an resources from your machine.
Having a machine hosted ( anywhere ) will be exposed, this is why we have enabled this option in the PBX side.
Already enabled, but the machine is still flooded regardless. I formerly had a machine hosted in AWS and implemented firewall rules to simply disregard the port.

Another option is the ability to simply change the port number which can be done on anything self-hosted, but not able to be done with 3CX Hosted to my knowledge.
 
@FleckTeck 3CX Hosted PBXs are vanilla PBXs so as you can understand customizations can not be done in this case. This is why we have Global 3CX Antihacking Defense Program enabled by default where if an ip address is reported, then the PBX will ignore by default all the requests.
For ip addresses that are not in th elist yet, then PBX has further security mechanism enabled in the Anti-Hacking section.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet