3cx system being DDoS'd

Status
Not open for further replies.

carlwright

Trial User
Joined
Dec 23, 2011
Messages
8
Reaction score
1
Hi

We seem to have a problem with our 3CX 15.5 system is periodically receiving a number of :

SIP request (REGISTER) from 82.69.xxx.xxx was rejected. Reason: Block WAN requests is ON.

From a variety of IP addresses.

This is causing the server to max out and knocking the system offline for a period of time.

We are chasing around blocking the IP addresses but can't seem to keep up.

Is there a good way to stop these coming through at the 3CX end or will it need to be handled by the firewall?

Thanks
Carl
 
So I seriously doubt the 'DDoS' is knocking your system offline. Since you gave no explanation of your setup I'm going to assume you have a misconfigured device connecting from the same location as legitimate devices and when the misconfigured device triggers the blacklist settings all devices connecting from that IP are getting blocked giving the appearance of the system being offline.

Also, there is no firewall in 3CX. 3CX has a security module which will try to protect against invalid attempts to access but it is not a firewall and does not stop those attempts from consuming resources. You will need to protect your instance at the edge, be it your router/firewall if in-house or the firewall/ACL settings for your selected cloud provider.

https://www.3cx.com/blog/voip-howto/securing-hints/
 
3Cx is probably doing all it can at this point, a properly configured firewall is the best defence.
 
Thanks for you input, yes we blocked the rogue IP address and this seems to have fixed the problem in the short term.

We're going to reconfigure the firewall to try and catch these flood attacks more logically so we don't have to spend time chasing bad register attempts.

Thanks
Carl
 
  • Like
Reactions: YiannisH_3CX
Hi Carl,

In order to prevent this ocurring in future you can do two things.

1. Only use VPN or SBC \ Tunnel for remote extensions
2. With the exception of the IP ranges of your SIP providers block all inbound traffic on port 5060 on your firewall.
 
Thanks. We have now taken your advice and blocked 5060 to our SIP provider only.

I don't know if this is related but we have also had the public IP address of the 3cx server blacklisted for too many failed authentications. Should this happen? It looks like the attempts are looking like this (with xxx.xxx.xxx.xxx as the 3cx IP address and yyy.yyy.yyy.yyy as the ip address of another of our public ips in our range):

SIP request (REGISTER) from xxx.xxx.xxx.xxx was rejected. Reason: Block WAN requests is ON.
Message:
REGISTER sip:yyy.yyy.yyy.yyy SIP/2.0
Via: SIP/2.0/UDP 37.49.231.156:5510;branch=z9hG4bK-1411901726;rport=5510;received=xxx.xxx.xxx.xxx
Max-Forwards: 70
Contact: sip:[email protected]
To: "102" <sip:[email protected]>
From: "102" <sip:[email protected]>;tag=3130323a6262626262620134303130353239353539
Call-ID: 999402763
CSeq: 2 REGISTER
Accept: application/sdp
Proxy-Authorization: Digest username="102",realm="3CXPhoneSystem",nonce="414d535c119700a788:f6d9f2b9fd5373eaeb2c38dd73bdb3e2",uri="sip:yyy.yyy.yyy.yyy",response="17474aff44b9417f463dac32090bcb0b",algorithm=MD5
User-Agent: PBX
Content-Length: 0
 
Reason: Block WAN requests is ON.

In this case, it suggests that you have chosen not to allow that particular extension to register outside the local network.
 
Probably a device is miss-configured and it is trying to register to the PBX using the public IP instead of the internal route and since the option to not allow the extension to accept Register requests from public locations the IP was blacklisted after a few failed attempts.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,893
Messages
589,597
Members
164,760
Latest member
SaschaA_