3CX SBC Questions

Status
Not open for further replies.

Tahir

Customer
Basic Certified
Joined
Dec 15, 2007
Messages
102
Reaction score
4
Hi,
I was speaking with support on another case i was told the following:

'In regards to the logs being very large, in a capture you previously sent, I noticed a lot of registrations coming through the tunnel (from the SBC) with User Agent: Asterisk PBX.
By checking the SIP packets I can be quite certain that it is a hacking attempt.
This was quite a lot of traffic so this might be what was causing it. However I cannot be sure of this, the above is just as an assumption.
For the above to happen, it is quite possible that port 5060 is open on the firewall of the SBC and forwarded to the SBC. If this is the case, please close the port as the SBC does not need any port forwarding to function.

I am not referring to the PBX firewall. I am referring to SBC firewall. Check if port 5060 is open and forwarded to the SBC on the site where the SBC resides. If it is, close the port as the SBC does not need to have this forwarded to function.'

Am i correct in assuming that the router firewall (public/internet facing) does not need to have port 5060 open and pointing to the SBC? Or is the above requesting something entirely different?

Regards

Tahir
 
  • Like
Reactions: Tahir
Thanks for the reply and confirmation.

Is there a way to secure the PBX from potential hacking/brute force? Is it best practice to lock down the comms to the SIP providers IP only?
 
https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/

https://www.3cx.com/docs/voip-security/

Best practice for security too would be things like:- secure passwords, IP access control from your SIP provider, 3CX MGMT console restriction by IP, selecting only the countries you'll be dialling, being very specific with your outbound rules.


3CX is pretty secure anyway. But, like anything on the internet, if it's public, someone will attempt to hack it. Go take a look at the security tab in 3CX MGMT console.

If you lock 5060 down to your SIP provider you will have trouble with remote devices registering unless you start whitelisting on your firewall. If all your remote sites are using SBC then sure lock it down. If all your remote sites have static WAN addresses then you could start locking down there too.

PBX has good anti-hack features by default. Just ensure users are not changing their passwords to something simple (check mgmt console ext page) check there are no warning triangles indicating weak passwords.

3CX will also tell you that the PBX should be your last line of defense and your HW firewall should be doing the work.
 
You can enable the Global Blacklist in your management console (Settings > Security)

12642

This will minimize the attempts a lot because the system will deny well known attackers. Available in V16.

You can also block 5060 for any IPs other than your provider, but this will block any STUN phones you have. Set your 3CX Apps to use the tunnel so they will not need 5060 at all.
 
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,818
Members
164,811
Latest member
aurorasigntrtechitnet