Automatic Global 3CX IP Blacklist

Status
Not open for further replies.

sip1

Gold Partner
Joined
Aug 25, 2014
Messages
6
Reaction score
0
Hello all,

Quick question.If i enable the automatic global 3CX IP blacklist feature on my customers tenancy and there is an issue with the customers remote site where the passwords are not authenticating for whatever reason and they end up being blacklisted several times, will their IP address be added to the global list? If so is it possible to get that IP address removed?

I have quite a few customers that work remotely and we have had issues in the past where their IP addresses have been blacklisted. I just want to make sure that enabling this feature wont permanently block them from accessing the phone system.
 
I can't speak 100% authoritatively, but it wouldn't make sense to let a single 3CX instance dictate what goes on the global blacklist. It would make sense that 3CX would need to see hits across multiple 3CX instances from the same IP before they put it on the global list. The exact number is not published for obvious reasons.

And of course, you can always white list which should supersede the global blacklist but it's hard to confirm without first being on the blacklist. @JohnS_3CX can you confirm this behavior?
 
Thanks Cobaltit,

That does make sense. I can't really whitelist the IP address due to it not being static, so they will get a new IP address every now and then.
If the global system only adds IP addresses that several instances report then i don't see an issue with this system for me.
 
I can neither confirm nor deny, but I think you should be fine if you enable it ;)
 
  • Haha
Reactions: Ipcomdavosander
@JohnS_3CX

Hah, fair enough. Can you at least confirm if the white list would override global blacklist entries?
 
@cobaltit Yesterday it did not seem to be so, one of our IPs made it to the global blacklist, and adding a whitelist entry did not seem to solve the problem, we had to disable the global blacklist option, and then magically everything worked again.

The blacklist/whitelist in the Management Console works via the Management console service and blocks logins, but allows you to still see the login page. However the global blocklist seems to be directly tied into the nginx web server process, and actually blocks every request with 403 forbidden if you are on the global blocklist, they appear to be using two different mechanisms...
 
Last edited:
@BrenttG Were you able to get the IP removed from the global blacklist? Did you also get a notification that the IP address was added to the global blacklist at all?
This is what i am concerned will happen with my customers.
 
There was no notification that it was added we only discovered it when we started having server report offline that weren't really offline and discovered just by troubleshooting that if we turned off the global blacklist they magically came back online.

I put in a ticket with 3cx to check and if so have it removed and they did.
 
@BrenttG
This is what i am concerned will happen with my customers.

You don't need to worry about it. BrenttG's scenario is quite different. Barring some major screwup on the part of 3CX the only way to get on the blacklist is if you get blacklisted locally on multiple 3CX instances.
 
You don't need to worry about it. BrenttG's scenario is quite different. Barring some major screwup on the part of 3CX the only way to get on the blacklist is if you get blacklisted locally on multiple 3CX instances.

Agreed, my scenario is outside the norm, and very unlikely you will have issues.
 
Hi
have you noticed a real decrease in intrusion attempts since the introduction of the global blacklist?
some days i have always same IP's doing hacking attempt on several pbx , i'm always wondering how is it possible?
how many pbx need to be attacked before something is in action on 3CX side? for how many times? are blacklisted ip's stay blocked from time set on our pbx and then when time is over, are they free to restart same problem again and again?

I find it really annoying not to have general information on the behavior of this feature, don't understand what is the need to be keep this like a government secret.

it's like often, we invent laws to prevent problems caused by a few bad sheep that finally annoy more people who respect the rules, others continue to do what they want
 
Last edited:
  • Sad
Reactions: StefanW
Hi aws2p,

I do not agree with your comment.

3CX is the first PBX which brings this kind of cloud defence to the market and of course, we protect how we do it. Since the introduction of this feature, the reported attempts of known bad IPs has drastically been reduced and the number of call frauds been reduced to next to nothing. Just to extend, all reported call frauds have administrative errors allowing call frauding which is no default setting or it goes without warning to the admin.

For the sake of clarification, it needs more than 1 report and we analyse patterns.
Additional, a manual white list entry will count more than any blacklist entry.
 
  • Like
Reactions: Evolute IT and Zol
Hi @StefanW

I do not dispute at all the legitimate efforts of 3CX for the security of the PBX, just that I think not to have general information on the operation of the blacklist, such as: what is the duration of blocking IP addresses blacklisted ? Are they banished forever? How many machines are needed to activate the blacklist process?
Is it possible to delete IP's in pbx blacklist if they are on global blacklist?


I don't ask 3CX to reveal how you do security and give technical details.

is that kind of questions so secret than it can compromise protection?
 
I do not dispute at all the legitimate efforts of 3CX for the security of the PBX, just that I think not to have general information on the operation of the blacklist, such as: what is the duration of blocking IP addresses blacklisted ? Are they banished forever? How many machines are needed to activate the blacklist process?
Is it possible to delete IP's in pbx blacklist if they are on global blacklist?


I don't ask 3CX to reveal how you do security and give technical details.

is that kind of questions so secret than it can compromise protection?

I too give 3CX big props for their security improvements since version 14, its a night and day difference to a factor of 10. This being said, even if all the details are not revealed, a "general" laymen's piece of documentation on its function should be made available, such as how to find out if you have been blocked, and how to submit information to 3CX to prove the legitimacy of the IP, or make a case as to why an IP shouldn't be blocked.

The problem is, Our IP that was blocked, was so for 3 weeks or so, We were investigating the problem on and off in free time for all of that time, thinking we had some configuration problem somewhere, or a network routing issue, when in reality it was the global list. We aren't asking for the secrets to the universe, just a few safe bits so we are not left scrambling in the dark.

Let us remember, that security by obscurity is not security at all, Avayao_O believed in that approach, and their IP500 is known as complete hacker bait as a result. But then again, Avaya was never much good at anything...

Security Through Obscurity (STO) is the belief that a system of any sort can be secure so long as nobody outside of its implementation group is allowed to find out anything about its internal mechanisms.
 
Last edited:
  • Like
Reactions: AWS2P
Security Through Obscurity (STO) is the belief that a system of any sort can be secure so long as nobody outside of its implementation group is allowed to find out anything about its internal mechanisms
Love this STO ;)
 
Well getting off the blacklist seemed easy enough (opening a support ticket) but documenting that couldn't hurt. Perhaps a page to check if an IP exists, maybe available only through the partner portal? By the same token, perhaps a way to submit IP's to auto-whitelisting via the Instance Manager to push down to our customers, or a way to keep them off the global blacklist for folks like @BrenttG who provide services that are more likely to trigger the mechanism would be good.
 
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,818
Members
164,811
Latest member
aurorasigntrtechitnet