Blocking 3CX Management Console from public

Status
Not open for further replies.

danielteng

Customer
Joined
Jan 28, 2022
Messages
18
Reaction score
0
Hi,

I would like to block all access to the 3CX Management Console from the internet and only be accessed on the internal network.
However, I would like our staff to be able to still access from home (Work from home). What I have tried.

1) Block access within management console to refuse public IP login. (Works but would like to further block by not showing the management console at all if access from public IP.)
2) Blocked from firewall to access HTTPS and HTTP internally. (Doesn't seem to work)
3) NGIX service was off and the seems to work (Will the system still work as per normal if this service is off?)

Thanks
 
You can restrict it by going to Security >> Console Restrictions.
 
hi jcostlow, i did the console restrictions as in point 1. however the management console can still be accessed from public just that you cannot login. would like to totally remove access to the console as it is a security concern.
 
If you want to do this, you'll need to block it at the firewall level (I think you tried this in your #2).

Can you elaborate on what "doesn't work" means?

Note the management port is used by the 3cx clients for presence, webclient (possibly other things as well) and blocking it can break things.
 
Hi SweetAction,

Thanks for the help.

I did a Deny for All TCP sources to any SRC port to our Public IP 443. Am I doing something wrong here?
 
I don't know what type of firewall you have, but typically what you do is set the IP list in the source area for the firewall rule that passes traffic to port 5001 (or 443).
 
Can I check with blocking the traffic to port 443, will the devices connected by softphone cease to work?
 
if 443 is the port you initially installed pbx with and not 5001, then blocking 443 will block presence
 
Thanks. I still have the issue of unable to block though. I am using cisco meraki if that helps
 
Update: manage to block access to the management console. however the presence does not show as aws2p says. how do i change the port to check the presence to 5001?
 
To change the HTTPS Port you have to re-install the PBX, using a backup of the current setup to restore your config. However, the HTTPS port is both used for accessing the Management Console and presence information so you cannot block one and keep the other, blocking the port means you lose both.

If your remote sites where the 3CX Clients/Apps reside happen to have static IPs, I guess you could block every other IP and only whitelist those, but you'll have to determine if this is a viable solution for your particular situation.
 
Ah. Thanks ChrisC. This would mean there is no way to block then. Our 3CX Clients are using Softphone so there is no way to go by IP.
Thanks.
 
Ah. Thanks ChrisC. This would mean there is no way to block then. Our 3CX Clients are using Softphone so there is no way to go by IP.
I don't think so, not without also blocking the softphones at least.
 
To change the HTTPS Port you have to re-install the PBX, using a backup of the current setup to restore your config. However, the HTTPS port is both used for accessing the Management Console and presence information so you cannot block one and keep the other, blocking the port means you lose both.

If your remote sites where the 3CX Clients/Apps reside happen to have static IPs, I guess you could block every other IP and only whitelist those, but you'll have to determine if this is a viable solution for your particular situation.
Would be great for Security, Console Access to allowing adding FQDN's, in addition to IP addresses!
 
Would be great for Security, Console Access to allowing adding FQDN's, in addition to IP addresses!
Since we're talking about incoming connections only I'm not sure how this would be useful. In any case, this is not possible as you can only add IPs.
 
Since we're talking about incoming connections only I'm not sure how this would be useful. In any case, this is not possible as you can only add IPs.

It would be *incredibly* useful because with an FQDN, that I control, the 3CX server would only allow the IP address that my FQDN resolves to. With FQDN, instead of only IP Address, all my techs can have their own unique IP Address that we don't have to worry when it changes. What you think?

BTW, my post about this idea got deleted bc I can't submit ideas, which is limiting.
 
  • Like
Reactions: ChrisC_3CX
BTW, my post about this idea got deleted bc I can't submit ideas, which is limiting.
As @jcostlow said, a certain partner level is required for posting in the Ideas section so you could maybe ask one with the appropriate permissions to post it on your behalf.
 
As @jcostlow said, a certain partner level is required for posting in the Ideas section so you could maybe ask one with the appropriate permissions to post it on your behalf.
Isn't there some way to edit the 3cx nginex web site folder or pages to limit what IP's can connect?
 
Isn't there some way to edit the 3cx nginex web site folder or pages to limit what IP's can connect?
I think you mean is there some supported way and the answer is no. Of course there is a way to change the nginx config.
 
Status
Not open for further replies.

Latest Posts

Members Online Now

Forum statistics

Threads
111,832
Messages
589,278
Members
164,662
Latest member
DejanMDS