3CX server open to internet access

Status
Not open for further replies.

o3 admin

Free User
Joined
Nov 21, 2019
Messages
9
Reaction score
1
hi all,

we already have a 3CX server used internally. with SIP trunks with our provider for external calls. we have a new requirement to open the server to public (internet) access so employees can login using the cellphone clients and make calls to the outside through the SIP trunks.

is that safe? I have been warned about "toll fraud" and concerned about loss of credit due to unauthorized calls through our SIP trunks.

a friend advised using a "Session Border Controller" is that necessary? do you suggest another solution?

I look forward to your advice.
 
You will need to open the ports for your MGMT console as per this article to access resources outside the PBX network.

https://www.3cx.com/docs/manual/firewall-router-configuration/

3CX mobile app uses the SBC feature.

As long as you dont adjust the anti-hacking settings within Security > Security Settings you'll have no problem.

turn on the automatic global 3CX IP blacklist and also use the console restriction feature.

I've got 50+ 3CX installs in the cloud with public facing services and have had no problem whatsoever.
 
  • Like
Reactions: o3 admin
You will need to open the ports for your MGMT console as per this article to access resources outside the PBX network.

https://www.3cx.com/docs/manual/firewall-router-configuration/

3CX mobile app uses the SBC feature.

As long as you dont adjust the anti-hacking settings within Security > Security Settings you'll have no problem.

turn on the automatic global 3CX IP blacklist and also use the console restriction feature.

I've got 50+ 3CX installs in the cloud with public facing services and have had no problem whatsoever.

thanks for your detailed response.

I've just checked the SBC article on the 3CX Website:

https://www.3cx.com/docs/3cx-tunnel-session-border-controller/

When is an SBC overkill?

If you have a single remote phone that you wish to connect to your 3CX in the cloud, consider using the 3CX iOS and Android Apps instead. 3CX Apps are the modern way to connect to a phone system. The user can use it anywhere in his home, or indeed even outside, and it will save configuration and maintenance.


is that a different point? do I still need the SBC as you said? or the iOS/Android Apps don't need SBC?

I hope you can help a bit more.

Thanks again.
 
thanks for your detailed response.

I've just checked the SBC article on the 3CX Website:

https://www.3cx.com/docs/3cx-tunnel-session-border-controller/




is that a different point? do I still need the SBC as you said? or the iOS/Android Apps don't need SBC?

I hope you can help a bit more.

Thanks again.
The SBC is for desk phones and the like and is used at static sites.

the mobile app has a built in SBC that tunnels back to the PBX.

Could you imagine how ridiculous it would be to have an external SBC whenever you moved with your phone? Think about it.

On that same website:

When do you need to install an SBC?

The most important usage scenario of an SBC is to connect a number of IP phones located in an office to a PBX located in the cloud. Another scenario is to connect to 3CX installations via a bridge.
 
  • Like
Reactions: o3 admin
The SBC is for desk phones and the like and is used at static sites.

the mobile app has a built in SBC that tunnels back to the PBX.

Could you imagine how ridiculous it would be to have an external SBC whenever you moved with your phone? Think about it.

On that same website:

When do you need to install an SBC?

The most important usage scenario of an SBC is to connect a number of IP phones located in an office to a PBX located in the cloud. Another scenario is to connect to 3CX installations via a bridge.
right, I agree. thanks it's just that you said: "3CX mobile app uses the SBC feature" I thought I need to enable SBC on my server to support the app. I misunderstood your message.

Thanks again for your support.
 
A bit off topic, but still within the realm. I currently running a demo set-up, which is exposed to net. Unfortunately, there have been a lot of attacks from user agents. So, I started selectively blocking the IP addresses. The problem arises with the delay in realeasing the ip from the blocklist. The default configuration of the blocklist feature is configured in days and I would like to change that.

2nd issue, where are all the IPs that are blocked that are globaly used?

3rnd why do I get some many notifications via email?

examples:

user agent A tried to access MY SIP truck. ---> fails X times -----> goes on blocklist for Y time.-------> then is released

At the same damn time:
user agent B tried to accesses YOUR SIP truck. ---> fails U times -----> goes on blocklist for W time.-------> then is released

Global database block list:

user agent A is blocked for Y minutes
user agent B is blocked for W minutes

My database block list:

user agent A is blocked for Y minutes
user agent B is blocked for W minutes


I get an email stating that user agent A is blocked. I visit my dashboard for blocked IPs and I don't see a thing.
Being a clever IT guy, I try to update the list with the with the details of the user agent A attack. Such as IP. Unftortunately, the IP is allready registered in the Global database, so I can't add it or modify it's block time.

Now, I am worried that the user agent A once off the block list, will try his/her abusive attacks again an will generate another blocked IP and email and so on and so on.

The clients Blocklist database should have an authority feature so that an IT guys like me can overide the default block time of a blocked IP and prevent subsequent attacks from that same IP.

How do I break the cycle of abuse without changing the plan for the customer? It's a never eding loop frustrations and spam.

Any insight would be appreaciated.
 
A bit off topic, but still within the realm. I currently running a demo set-up, which is exposed to net. Unfortunately, there have been a lot of attacks from user agents. So, I started selectively blocking the IP addresses. The problem arises with the delay in realeasing the ip from the blocklist. The default configuration of the blocklist feature is configured in days and I would like to change that.

2nd issue, where are all the IPs that are blocked that are globaly used?

3rnd why do I get some many notifications via email?

examples:

user agent A tried to access MY SIP truck. ---> fails X times -----> goes on blocklist for Y time.-------> then is released

At the same damn time:
user agent B tried to accesses YOUR SIP truck. ---> fails U times -----> goes on blocklist for W time.-------> then is released

Global database block list:

user agent A is blocked for Y minutes
user agent B is blocked for W minutes

My database block list:

user agent A is blocked for Y minutes
user agent B is blocked for W minutes


I get an email stating that user agent A is blocked. I visit my dashboard for blocked IPs and I don't see a thing.
Being a clever IT guy, I try to update the list with the with the details of the user agent A attack. Such as IP. Unftortunately, the IP is allready registered in the Global database, so I can't add it or modify it's block time.

Now, I am worried that the user agent A once off the block list, will try his/her abusive attacks again an will generate another blocked IP and email and so on and so on.

The clients Blocklist database should have an authority feature so that an IT guys like me can overide the default block time of a blocked IP and prevent subsequent attacks from that same IP.

How do I break the cycle of abuse without changing the plan for the customer? It's a never eding loop frustrations and spam.

Any insight would be appreaciated.
You simply change the blacklist duration to the maximum which I believe is above 20 years. The global blacklist is handled externally as noted when you opt in to it. And, I would turn off the notification for blacklist.
3CX will tell you that the pbx should not be the first line of defence in blocking attacks. You should look to secure your network parameter by locking down ports/IPs if you’re that paranoid.
 
Hi @stringmusic,

For the use of the mobile client, you only need to open ports SecureSIP port 5061 (default) and the Tunnel port 5090 (default). Here is a list of the ports we use and their descriptions.

Unfortunately, there have been a lot of attacks from user agents.

You could enable "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)" on the extension level to avoid these attacks.
 
Status
Not open for further replies.