- Joined
- Nov 12, 2019
- Messages
- 19
- Reaction score
- 3
hi team,
recently we got a few alerts from our firewall that indicating the 3cx server (10.8.3.150) is trying to initiate connetions to 10.8.2.1 on UDP 5060. I need some help to understand why the server would proactively do this?
Message meets Alert condition
date=2022-10-13 time=01:42:06 devname=ams-firewall1 devid=FGT61ETK18009136 logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1665618126153041382 tz="+0200" srcip=10.8.3.150 srcport=5060 srcintf="internal3" srcintfrole="undefined" dstip=10.8.2.1 dstport=5060 dstintf="internal2" dstintfrole="lan" sessionid=335857025 proto=17 action="deny" policyid=114 policytype="policy" poluuid="5279c884-d2a1-51e9-7f33-ba70451677fb" service="SIP-UDP-5060" dstcountry="Reserved" srccountry="Reserved" trandisp="noop" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel="high"
Message meets Alert condition
date=2022-10-13 time=01:42:02 devname=ams-firewall1 devid=FGT61ETK18009136 logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1665618122143029383 tz="+0200" srcip=10.8.3.150 srcport=5060 srcintf="internal3" srcintfrole="undefined" dstip=10.8.2.1 dstport=5060 dstintf="internal2" dstintfrole="lan" sessionid=335856833 proto=17 action="deny" policyid=114 policytype="policy" poluuid="5279c884-d2a1-51e9-7f33-ba70451677fb" service="SIP-UDP-5060" dstcountry="Reserved" srccountry="Reserved" trandisp="noop" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel="high"
10.8.2.1 is in our local subnet ranges but not the voice subnet we use. Nonetheless, in what situations would the server initiate the SIP connection to a host? I cant seem to find a configuraiton item for this IP, so Im wondering where did the system pick up this IP.
recently we got a few alerts from our firewall that indicating the 3cx server (10.8.3.150) is trying to initiate connetions to 10.8.2.1 on UDP 5060. I need some help to understand why the server would proactively do this?
Message meets Alert condition
date=2022-10-13 time=01:42:06 devname=ams-firewall1 devid=FGT61ETK18009136 logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1665618126153041382 tz="+0200" srcip=10.8.3.150 srcport=5060 srcintf="internal3" srcintfrole="undefined" dstip=10.8.2.1 dstport=5060 dstintf="internal2" dstintfrole="lan" sessionid=335857025 proto=17 action="deny" policyid=114 policytype="policy" poluuid="5279c884-d2a1-51e9-7f33-ba70451677fb" service="SIP-UDP-5060" dstcountry="Reserved" srccountry="Reserved" trandisp="noop" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel="high"
Message meets Alert condition
date=2022-10-13 time=01:42:02 devname=ams-firewall1 devid=FGT61ETK18009136 logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1665618122143029383 tz="+0200" srcip=10.8.3.150 srcport=5060 srcintf="internal3" srcintfrole="undefined" dstip=10.8.2.1 dstport=5060 dstintf="internal2" dstintfrole="lan" sessionid=335856833 proto=17 action="deny" policyid=114 policytype="policy" poluuid="5279c884-d2a1-51e9-7f33-ba70451677fb" service="SIP-UDP-5060" dstcountry="Reserved" srccountry="Reserved" trandisp="noop" duration=0 sentbyte=0 rcvdbyte=0 sentpkt=0 appcat="unscanned" crscore=30 craction=131072 crlevel="high"
10.8.2.1 is in our local subnet ranges but not the voice subnet we use. Nonetheless, in what situations would the server initiate the SIP connection to a host? I cant seem to find a configuraiton item for this IP, so Im wondering where did the system pick up this IP.