3cx IP Range

Status
Not open for further replies.

kbayar

New User
Joined
Sep 10, 2021
Messages
1
Reaction score
0
I'm trying to configure my firewall against VOIP/SIP attacks. In this context, I configured the FW in the following way...

For Local3cx to WAN policy:
"""
From: local 3cx vlan
To: WAN
Service: (some other required services for windows update and others like HTTP,HTTPS and.... IP range of my sip provider_ALL_UDP_TCP
"""

Explanation: for outgoing UDP/TCP traffic from on-premise 3xc to WAN, only the IP range of my sip provider is allowed

For WAN to Local3cx policy:
"""
From: WAN
To: Local3cx
Service: 5001 TCP (it's web UI port for accessing https and only 1 ip is allowed), 5060 UDP (registration port for SIP provider and only our SIP provider's ip range is allowed for this port accessing), 9000-10999 UDP (only our sip provider's ip range is allowed for accessing those ports) 5090 TCP and 5090 UDP (I THINK THESE 2 PORTS SHOULD BE ACCESSIBLE FROM 3CX'S IP RANGE)

The question is that what is the IP Range of 3CX so that I use it in WAN to Local3cx policy for security?
 
Hi @kbayar ,

I think you should go over this academy module that explains a few things surrounding this topic you brought up:
https://www.3cx.com/3cxacademy/videos/basic/nat-port-forwarding/

Also don't forget to allow outbound traffic to activation.3cx.com to avoid having problems (re-)activating your license and to downloads-global.3cx.com to get firmwares, service packs, template updates, etc.
Unfortunately these IPs are not static as they are on CDN, so there is no specific IP range I can tell you.

5090 TCP and 5090 UDP (I THINK THESE 2 PORTS SHOULD BE ACCESSIBLE FROM 3CX'S IP RANGE)
No, each individual Remote Mobile App user's or 'legacy' Windows App user's IP would need to be allowed here, so unless you know who will be connecting and from where, and they have static IPs, I don't see this being possible.
 
You can see the ports that need to be opened from this website: Ports Used by 3CX Phone System v15+
Basically you'll need for sure these ports, open from all remote IPs:
- 5001 TCP - Web config and client
- 5090 TCP/UDP - APPs & SBC ports (not mandatory but apps will not work without)
- 5060 TCP/UDP from your public cloud provider (not mandatory but highly suggested)
- 9000 to 10999 UDP
plus:
- 5015 TCP if installing PBX from outside your LAN, so this is temporary
You can protect web config login in security, enabling only your static IPs to access.

And disable SIP-ALG on your firewall !!!!! :D
 
  • Like
Reactions: NickD_3CX
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,977
Messages
590,097
Members
164,906
Latest member
Nari