Automatic Global IP Blacklist doesn't respect Allow listed IP's

frozencrow

Premier Customer
Basic Certified
Joined
Oct 2, 2024
Messages
21
Reaction score
2
Currently using the softphone an a network that's connected to a VPN and when I try to log in I get a message saying the IP address is blacklisted.
I added the IP as Allowed in the IP Blacklist tab but still doesn't work.

The only way I can get it to work is by disabling the Automatic Global IP Blacklist checkbox. But it seems that the highest precedence rule should be manual allows configured in the PBX. Is this a bug or a feature?
 
The Global blacklist will take precedence.

The question that should be asked is WHY its on the Global blacklist. In order for this to happen this IP address would have been known to us for MULTIPLE access attempts to MULTIPLE systems.
 
  • Like
Reactions: EmmettsIT and bitn2
Seems like it would be a challenge for VPN users as there may be multiple connections over a single IP. Theoretically, couldn't that just be the result of multiple users on a single VPN forgetting their password and failing login a few times?
 
The screening of IPs going into the global blacklist is NOT an automated process. For an IP to go into that list, someone abused the system.
 
So in the event that I have a user of the system that can't access because they're on that list and i'm pretty sure they have not abused the system. What's the best course of action?
 
Seems like it would be a challenge for VPN users as there may be multiple connections over a single IP. Theoretically, couldn't that just be the result of multiple users on a single VPN forgetting their password and failing login a few times?
Hackers use many different methods to hack there targets, Web Servers, VPN services and the list goes on. If you are using a VPN and someone using the same service and the same IP to try to force into a 3CX server, you can bet it is on the Blacklist IP. The only way to prevent this is to not use a VPN
 
So in the event that I have a user of the system that can't access because they're on that list and i'm pretty sure they have not abused the system. What's the best course of action?
If you are using the VPN service solely to connect onto 3CX, then you dont need to use it, as the tunnel and HTTPS connections to the PBX are already secure, and you are essentially adding overheads to existing overheads.

The decision to add an IP to the global blacklist is not one that is taken lightly, but they are there for a reason.
 
To answer your question I think you first need to find out more about this user's VPN (assuming it isn't already under your control).

But I must say that the situation sounds like all kinds of wrong to me... the best case scenario is that the user's VPN uses an IP address blacklisted by a previous tenant, and I can understand a reluctance from 3CX to remove that blacklisting as it's likely there for a very good reason.

The worst case scenario is the user is a bad actor or their network has been compromised by a bad actor (actually, the very worst scenario would be that you are the user / bad actor, but hopefully that isn't the case :) ). There are other possibilities between those extremes, but none of them are great... and I think this is for the user to fix their blacklisting problem rather than you, especially given the same IP address has probably tripped security measures in other places as well so this is unlikely to be their only problem.

I'm no security expert, but the scenario you have outlined is enough to worry me about the user.
 
From previous responses it seems there is no mitigation process for being on the blacklist. It's all automated which means that either people or AI/Algos are making decisions and then following some sort of internal logic on how long an IP remains blacklisted.

Based on my knowledge of the user my assumption is they are not a bad actor but could be on a shared VPN that has been or is being used by others irresponsibly.

Unfortunately since some amount of the system seems to be based on security through obscurity I don't think it will be easy to mitigate these issues, which is why I thought being able to override IP's in our individual hosted instance would make sense as it ultimately leaves the risk to us. But, it works how it works for now.
 

Latest Posts

Forum statistics

Threads
111,962
Messages
589,993
Members
164,867
Latest member
swegner