A lot of Blacklisted IPs

Status
Not open for further replies.

Phil_Z

Joined
Feb 7, 2018
Messages
5
Reaction score
1
Hi folks,

my 3CX PBX works perfectly fine. But I don't know how to feel about one thing:
Every day the number of blacklisted IPs keeps rising. (see screenshots at http://root.druck-drauf.de/temp/3cx/).

Is that normal or very unusual? Am I supposed to do something?

Philipp
 
I have a few hundred in my blacklist. It will start to level off after you have gone in and changed the expiry date to something, many years in the future. If you use the same year, say 2040, it makes it faster to scan the list looking for any new ones. When you start to see attempts from similar IPs. that's when you start to block ranges. I find that now I get about 3 a week on average.
 
eventually, you may identify ranges and block them at the network firewall level.
 
I have my SIP (port 5060) firewall locked down to my SIP provider and the IP's of the remote offices. Is there a reason you can't do that?

Remote clients (Windows, iOS and Android) should be using the tunnel port so there's no need to leave 5060 open for those.
 
That's a very good point to be made here...
 
I have 4 systems (2 Google, 1 AT&T, 1 Spectrum) all with the same hits in the last 24 hours. This seems to indicate possibly a targeted effort and that maybe the 3CX DNS entries are known. Since I don't have addition systems to compare yet I was just curious if others saw the same IPs in the last couple days

45.76.135.188
45.32.182.243
5.62.63.181
138.68.60.1
5.62.60.213
178.17.171.221

Ditto on blocking at the firewall, already started that.
If anyone has a good resource on Google's firewall I would appreciate a link to it. Please don't send the Google help links, been there it assumes you're already familiar with their jargon. I just need a site with some good example configs would be great.
 
Configure your firewall to only allow VoIP provider and 3CX IP's for TCP/UDP 5060-5061. Limit SSH to only your network. (3CX is required for the firewall checker to pass - get the STUN servers and also sip-alg-detector.3cx.com.
 
If anyone has a good resource on Google's firewall I would appreciate a link to it. Please don't send the Google help links, been there it assumes you're already familiar with their jargon. I just need a site with some good example configs would be great.

Go to VPC Network, Firewall Rules. You will probably have one rule added by 3CX called "pbxports". It will have all the ports needed for 3CX, and will allow traffic from anywhere - 0.0.0.0/0. Add a new rule, maybe call it pbxports-limited, set priority to the same as the pbxports rule, and add ALL of the IP addresses/networks for your SIP Trunk provider(s) and 3CX. Set the Protocols and Ports to "tcp:5060-5061; udp:5060-5061" and save the rule. Then, remove "tcp:5060-5061; udp:5060-5061" from the original pbxports rule.

Be sure to run the firewall checker when you are done. Test telnet to port 5060 to make sure it's closed for any IP that is not listed in the source IP list.

Hope this helps! Feel free to PM me if you need any more help with it.

Tim Schulte
AccentLogic
3CX Advance Certified
3CX Platinum Partner
 
Go to VPC Network, Firewall Rules. You will probably have one rule added by 3CX called "pbxports". It will have all the ports needed for 3CX, and will allow traffic from anywhere - 0.0.0.0/0. Add a new rule, maybe call it pbxports-limited, set priority to the same as the pbxports rule, and add ALL of the IP addresses/networks for your SIP Trunk provider(s) and 3CX. Set the Protocols and Ports to "tcp:5060-5061; udp:5060-5061" and save the rule. Then, remove "tcp:5060-5061; udp:5060-5061" from the original pbxports rule.

Be sure to run the firewall checker when you are done. Test telnet to port 5060 to make sure it's closed for any IP that is not listed in the source IP list.

Hope this helps! Feel free to PM me if you need any more help with it.

Tim Schulte
AccentLogic
3CX Advance Certified
3CX Platinum Partner


Lock down seems to be working but firewall checker now fails. I'm assuming because 3cx test servers are now blocked, any idea what those are, I don't see any listing for them?
 
Lock down seems to be working but firewall checker now fails. I'm assuming because 3cx test servers are now blocked, any idea what those are, I don't see any listing for them?

Yes, the firewall checker will fail until you add their STUN and SIP ALG check servers. These can vary based on your country, so I did not post, but here is what we use. The below subnets seem to contain all of the 3CX STUN and ALG check servers.

151.80.125.0/24
158.69.11.0/24
158.80.125.0/24
 
I didn't think to open up the whole range I just tried the specific address returned from stun, stun-us,stun2, stun3. Makes since.

Thanks
 
The entire blocks may not be necessary, but it looks like 3CX owns most of them, so we wanted to make sure changes withing the blocks don't cause failures. On top of the 3 STUN servers you also need to allow the IP for "sip-alg-detector.3cx.com". (151.80.125.90)
 
Status
Not open for further replies.

Forum statistics

Threads
111,893
Messages
589,595
Members
164,760
Latest member
SaschaA_