added security

Status
Not open for further replies.

shingpkp

Free User
Joined
May 30, 2019
Messages
3
Reaction score
0
is it possible when an IP address is blacklisted, this address would be automatically barred from registering as an extension? Logs are showing my system is being hack. I have naturally barred this on the firewall. It took me sometime to learn how to install and configure a firewall on Linus system, but I got there.

Also is it possible to change the default port 443 for logging into my 3cx system? My system is on a linus cloud host platform, I do not have access to the router.
 
Yes, being blacklisted will stop that IP from accessing the system completely and you will not be able to register from that IP.

The firewall should not reside on the PBX machine, but should be a different machine in front of your PBX or use your cloud provider's firewall.

You cannot change the HTTPS port unless you reinstall the system. Is this a PBX Express free instance hosted by 3CX or do you have it installed on your own hosting solution?
 
Thank you for your quick reply. Im using OVH vps cloud solution to setup my 3cx. There was no firewall or port forwarding options on the platform.

Yes normally I would agree firewall should be a separate device.
 
Hi @shingpkp

If you are new to 3CX and feel stuck or decide to rebuild the install, you can delete the machine and start over by using PBX Express rather than manually deploying.

This should set up the machine for you automatically, and take care of firewall rules too as it is all automated by us, and deployed into your own hosting solution in OVH. You can either log into your customer portal and click Keys, and then Deploy or you can go paste your key via https://pbxexpress.3cx.com/

Our OVH Guide: https://www.3cx.com/docs/cloud-pbx-ovh/

You can also use this as a base line or learning tool to build future manual installations if you wish.
 
Do not get sucked into a single layer of security strategy. The firewall is one of many tools that should be used to protect you and your client. In many cases the firewall is managed by another group or individual. Do you really want to assume their work is good to go? If you are using the Debian version, install IPSet and DenyIP spend a couple of hours learning how to enhance the Debian internal firewall IPTables with a single line to improve your security 10-fold.
 
Status
Not open for further replies.

Forum statistics

Threads
111,926
Messages
589,762
Members
164,799
Latest member
RicoDinero