5060 Full cone NAT - clarification; Secure or not?

Status
Not open for further replies.

RMINCHIN

Customer
Joined
Apr 28, 2014
Messages
6
Reaction score
0
Hi

I'm in the middle of an argument between my 3CX partner and my TI company that manages our firewall. We have upgraded to v15.5 and the firewall check is failing as it needs a full cone NAT on 5060.

Our IT company are saying this is unsafe to do and we should get a list of IP addresses from 3CX and only open the port to traffic from those addresses.

does anyone have a view as to the security issues of providing the 1:1 NAT on 5060 back to the pbx?

Regards
 
The rule of thumb with corporate firewalls is close everything and then only open the ports you need to the addresses / ranges you need so I would agree with your IT company.
 
Hello @RMINCHIN

Please note that this depends on the security requirements of your company. Port 5060 is used for SIP communication so you can configure the port to be accessible only by Voip providers or remote sites running IP phones.
Leaving port 5060 open to everyone means that you are open to SIP scans and hack attempts. The PBX has a very capable inbuilt security module to keep you protected but it cannot replace a firewall.
 
  • Like
Reactions: Lee Cramman
Our IT company are saying this is unsafe to do and we should get a list of IP addresses from 3CX and only open the port to traffic from those addresses.

The IP Addresses would be your providers and any remote offices using STUN.
Softphones on Mobile and phones behind an SBC would (read 'should') use port 5090.
 
Hello @RMINCHIN

Please note that this depends on the security requirements of your company. Port 5060 is used for SIP communication so you can configure the port to be accessible only by Voip providers or remote sites running IP phones.
Leaving port 5060 open to everyone means that you are open to SIP scans and hack attempts. The PBX has a very capable inbuilt security module to keep you protected but it cannot replace a firewall.


Hi YiannisH thanks for that - Our firewall checker was failing on a full cone NAt on port 5060, hence why our 3CX partner said we MUST open the port up to ALL traffic. Are you saying that's not the case? If so, will the checker succeed if we just give access to the provider's IP address? (P.s. Layman here very reliant on the opinions of the experts we pay to advise - hence why I'm a bit upset I'm even having to ask the questions on here!)
 
The IP Addresses would be your providers and any remote offices using STUN.
Softphones on Mobile and phones behind an SBC would (read 'should') use port 5090.

Thanks. A bit of a conundrum then when your 3CX partner is insisting you open it to all...
 
I would recommend opening all ports and run the 3CX firewall checker and make sure all ports pass the test. If you run the firewall checker with the ports only open towards your provider the tests will fail. If all tests pass then it is up to you to tighten your security. if you face any issues that you might think are firewall related you can always open then back up.
 
Status
Not open for further replies.

Forum statistics

Threads
111,899
Messages
589,620
Members
164,765
Latest member
domi