Blacklist IP Issues

Drain Bamaged

Premier Customer
Joined
Mar 6, 2020
Messages
68
Reaction score
18
We're having a couple of IP's continually hammering our PBX. When I set the server up I changed the default from 900 seconds in the IP Blacklist to a week:

1738093595542.png

Any remote users of ours can be unlocked in seconds, but for brute force attacks they can wait a week for a second attempt.

However, I started getting dozens of emails from the same IP's and realized a blacklisted IP was only blocked for 15 min or 900 seconds. (The server is in a different time zone)

1738093702101.png

Event log confirms this:

1738093750265.png

In order to stop this, I have to wait until the IP is in Blacklist, then manually update the expiration date by a week (or enter everything manually), which isn't a great use of my time. Not to mention my InBox flooded with alert emails. This is my afternoon so far.

1738094288456.png

So increasing the Blacklist time interval does nothing. If this function isn't "the time interval in seconds that an abusive IP Address remains in the blacklist" then what does this value do? These IP's are probably spoofed and I doubt the volume of attempts will go down.

We need these malicious IP blocked for longer than 15 min please.

Thanks.
 
Your first mistake was enabling the notification for blacklist.

You should know that ANY device on the public internet is susceptible to attacks, and bots will scan and try any device they get a response from.

You should leave the default values in 3CX, or look at being more restrictive at your firewall level.

Also, is that v18?
 
Your first mistake was enabling the notification for blacklist.

You should know that ANY device on the public internet is susceptible to attacks, and bots will scan and try any device they get a response from.

You should leave the default values in 3CX, or look at being more restrictive at your firewall level.

1738138943736.png

Also, is that v18?
 
We're having a couple of IP's continually hammering our PBX. When I set the server up I changed the default from 900 seconds in the IP Blacklist to a week:

View attachment 46183

Any remote users of ours can be unlocked in seconds, but for brute force attacks they can wait a week for a second attempt.

However, I started getting dozens of emails from the same IP's and realized a blacklisted IP was only blocked for 15 min or 900 seconds. (The server is in a different time zone)

View attachment 46184

Event log confirms this:

View attachment 46185

In order to stop this, I have to wait until the IP is in Blacklist, then manually update the expiration date by a week (or enter everything manually), which isn't a great use of my time. Not to mention my InBox flooded with alert emails. This is my afternoon so far.

View attachment 46186

So increasing the Blacklist time interval does nothing. If this function isn't "the time interval in seconds that an abusive IP Address remains in the blacklist" then what does this value do? These IP's are probably spoofed and I doubt the volume of attempts will go down.

We need these malicious IP blocked for longer than 15 min please.

Thanks.
The Blacklist time interval is for SIP registrations. Someone tries to register a SIP device then they will be blacklisted for the default time interval of 86400 seconds which is 24 hours. The maximum time interval is 1 biliion seconds (about 31.7 years)

The 900 seconds (15 minutes) is for web logins.
 
>The 900 seconds (15 minutes) is for web logins.

Thank you Nicolas. Is there a value we can amend to extend this time? If not, please add it to the wish list.
 

Latest Posts

Forum statistics

Threads
111,962
Messages
589,996
Members
164,868
Latest member
swegner