Solved Black List IP Range Bug

Status
Not open for further replies.

redbudindustries

Forum User
Joined
Feb 11, 2019
Messages
68
Reaction score
6
Version: 16.0.655
OS: Debian Linux
Location: On Prem
Edition: Enterprise

We have recently had a string of hacking attempts from an source that just increments its IP and tries again. I removed the individual entries and tried to black list the /24 range because its way out of state and we will likely never get legit user traffic from it. I can set the address as 45.86.211.0, the subnet to /24, and fill the rest of the info in but when I click OK to create the entry I get an error saying "This IP address is already in the blacklist." I searched but there are no entries for 45.86.211.X, and not even for 45.86.X.X so I don't understand why its telling me there are. Anyone know how to fix this?

I have tried
  • logging out and back into the management console.
  • restarting the browser and logging back in.
  • logging into Mgnt Console in different browsers: Edge, Chrome, Brave
This isn't critical enough to restart the server during business hours but I could tonight if that will help.

Thanks in advance.
 
This is most probably happening because one of those IPs is in 3CX's global black list. I actually just tested and can confirm that I get the same error when trying to block that range but then am able to enter it if I disable the global blacklist so that should indeed be it.

You could try disabling it too but to be honest I would not recommend it, Id opt for blocking one IP at a time and if these malicious attempts from these IPs are not only happening on your instance they will eventually be added to our global blacklist which evidently is already happening.
 
  • Like
Reactions: redbudindustries
Thank you for investigating that.
I understand your explanation but that seems like a poor way of doing things.
I know the IPs are malicious and I would rather not wait for the auto ban to catch them because that means they have thousands of possible attempts at my system. It seem inefficient to have to add up 253 address manually because even 1 is already on a completely different list.
If this is how things will continue to work then the error message should be changed and the blacklist documentation updated to help clarify this is how the system works.

Could I disable the global service, make my desired block range entry, and then turn the global back on? What is required to turn the global list off and on?
 
  • Like
Reactions: redbudindustries
That seems to have worked. Thank you for your help!
This post can be closed.
 
  • Like
Reactions: ChrisC_3CX
You're very welcome!

Feel free to post a new if you need anything else!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet