Solved Block management console via internet

Status
Not open for further replies.

GBC_James

Premier Customer
Advanced Certified
Joined
Feb 3, 2017
Messages
132
Reaction score
24
Hi all
So we've just had the results back from a penetration test of our network. One of the things that flagged up is that the 3CX management console is accescable over the internet.
So we need to restrict access to the management console, without impacting any other services, like reports, mobile app connectivity etc.
So how would we do this?
And here's the bonus question. Is it possible to restrict access to the console BUT allow me to access across the internet, because if I am on vacation or sick or whatever, in an emergency it's been really handy for me to get to the console on my ipad or phone and quickly make changes. It would be awesome if I could still do that, but everyone else be blocked.

am I making sense? any of this possible?

thanks
James
 
Hello @GBC_James

Since the management console is using the same port as the provisioning and presence means that if you block the port you will lose functionality. The access however is only via HTTPS and it only an issue if you are using a weak password. Also the management console will blacklist anyone after 3 wrong authentication requests.
 
  • Like
Reactions: craigreilly
Hello @GBC_James

Since the management console is using the same port as the provisioning and presence means that if you block the port you will lose functionality. The access however is only via HTTPS and it only an issue if you are using a weak password. Also the management console will blacklist anyone after 3 wrong authentication requests.

thanks YiannisH
I thought as much.

So I have a question from our Webmaster, who is involved in resolving our compliance issues (we are local government in the uk and have strict government code of connection policies to comply with)

Hi question is this;

"On the report it states:

Description:
The remote service accepts connections encrypted using TLS 1.0. TLS 1.0 has a number of cryptographic design flaws. Modern implementations of TLS 1.0 mitigate these problems, but newer versions of TLS like 1.1 and 1.2 are designed against these flaws and should be used whenever possible. PCI DSS v3.2 requires that TLS 1.0 be disabled entirely by June 30, 2018, except for POS POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptible to any known exploits.


Resolution
Enable support for TLS 1.1 and 1.2, and disable support for TLS 1.0.

Can you ask 3CX if we can do the resolution as stated?"

What do you think?
 
Please navigate to Settings / Security and enable the option under "SSL Transport and Ciphers".
 
Please navigate to Settings / Security and enable the option under "SSL Transport and Ciphers".

that's great. Nothing has stopped working, but then we don't have any old legacy phones and all clients and apps are fully up to date.

thanks very much
 
Glad i could assist
 
Status
Not open for further replies.

Forum statistics

Threads
111,900
Messages
589,629
Members
164,765
Latest member
domi