Blacklisted IP's for Too many failed authentication attempts

Status
Not open for further replies.

mgiara

SOHO User
Joined
Feb 19, 2022
Messages
38
Reaction score
6
Getting flooded with these.

I looked them up and they're all coming from China, India and Ukraine

My local network (Ubiquity) is setup to not allow any connections from a long list of countries, and as such I've stopped getting notifications of intrusion attempts.

Unfortunately the 3CX system is being hosted, so I can't put it behind my in-house firewall.

All of the numbers in the Anti-hacking menu that said "increase this value to disable security", I cut in half, and the blacklist timeout I changed from the default 24 hrs to 365 days

Anything else I can do? My boss and I are concerned but simply prepared to implement whatever measures you all suggest.

I understand that intrusion attempts are common, can come sporadically or in waves, and that the Anti-Hacking feature is doing its job as intended (I'm thankful for it). Just curious what else I can do on a hosted system.
 

Attachments

  • 3CXblacklist.png
    3CXblacklist.png
    345.8 KB · Views: 16
Under Security/Anti-Hacking, do you have "Automatic Global 3CX IP Blacklist" enabled?

Double check with wherever it's being hosted that they can't/won't block by country. We do that in our data center.
 
  • Like
Reactions: mgiara
Under Security/Anti-Hacking, do you have "Automatic Global 3CX IP Blacklist" enabled?

Double check with wherever it's being hosted that they can't/won't block by country. We do that in our data center.
Yes it is enabled.

It's being hosted by 3CX I believe?
 
The internet is a scary place. Turn off the alerts
 
hosted by 3CX
3CX has customers all over the world so probably can't even consider that. On a smaller scale there aren't usually firewall changes unless an owner leaves the country on vacation and needs their phone to work.

It's actually kind of useful to us because we either get all clients blacklist the same IP at the same time and can ignore it, or as I've learned if only one server blacklists an IP it's something we need to investigate. :) The former is about once every couple months I'd guess.

In Security/Console Restrictions you can allow your IP(s) and "Allow Access from specific IP Addresses" which will prevent other IPs logging in to the management console, though not the web client.
 
  • Like
Reactions: mgiara
allow only 5060 to sip provider IP, with that set on my cloud pbxs since years never got one iP blacklisted
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru