- Joined
- Feb 24, 2016
- Messages
- 246
- Reaction score
- 36
Hi!Are there logs of what credentials were used? I see the IPs that are black listed, and some of the show the device that was used. Some of the blacklists don’t show anything, and I am guessing that an extension was tried. I haven’t yet found a log showing this, nor an email containing credentials.
Note: I am seeing “things” with my Cisco RV160 rules, and am planning a move to a pfSense+ device. I have to budget that in while I figure out how to deal with these bursts of blacklists.
That's actually quite a common practice hackers use, masking their requests as "Polycom" or "Cisco", etc.The perpetrators seem to have moved on to trying to authenticate as devices, such as IP phones and other PBX devices.
Dave, whitelisting just means that the IP(s) in question will not be locked out. Making them "part of the network" is basically done through your firewall.I could just test this I guess, however I thought a quick question on here instead would save me the troubleand maybe of interest to other users
Does white listing an IP address mean that IP address is then considered part of the 'network' i.e. once whitelisted you then wouldn't need to uncheck the extension option - "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)"? if using STUN on that extension of course.
If that's not the case, might be something worth considering as it would keep the network more secure if you had remote workers working at home (on fixed IP addresses). Obv a SBC would be preferred, but sometimes a little overkill for remote workers where only one device on the connection.
Dave.
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.