Can access to the admin console be restricted?

Status
Not open for further replies.

Enrique_Enaitech

Bronze Partner
Joined
Jun 26, 2023
Messages
1
Reaction score
0
Due to the attacks we have experienced, I need to know if it's possible to restrict the admin console for certain IP addresses, either through a Firewall-level VPN or something similar.

If that's not possible, are you aware of any implementation that can be done to enhance security for access?

tnhx team.
 
Due to the attacks we have experienced, I need to know if it's possible to restrict the admin console for certain IP addresses, either through a Firewall-level VPN or something similar.

If that's not possible, are you aware of any implementation that can be done to enhance security for access?

tnhx team.
Console restrictions are built into 3CX. You can still load the page from a non-whitelisted IP, but you cannot login no matter what credentials are tried.

They also apply to web admin, where the button doesn't appear if not in a whitelisted IP.

You could block the HTTPS port on your firewall (5001/443) but that will break other things, like status in apps, sms, etc.
 
What SweetAction said, but IIRC it is not available in 3CX hosting/StartUP. Otherwise, Security/Console Restrictions. Consider adding more than one IP in case your Internet is out, or you get a new ISP.

If you have your own server you can run IDS on your firewall in front of 3CX.
 
For all our 3CX servers we limit access to the server by IP. This is a common firewall feature and is easily set up even on basic hosting platforms like AWS LightSail. Logically, we don't want these restrictions implemented by 3CX. We want the restriction performed BEFORE the "user" ever reaches the 3CX server.
 
  • Like
Reactions: Enrique_Enaitech
For all our 3CX servers we limit access to the server by IP.
So do you just not allow the web client from homes or other locations? Allow via dyndns hostname?

In hindsight it'd have been handy if 3CX had put the management console on another port, but... (hint, 3CX, that wouldn't be hard to do to split the two...3CX admins can handle adding a port and /webclient can redirect to / or vice versa for everyone else).
 
  • Like
Reactions: Enrique_Enaitech
One would presume that anyone working remotely would also need access to other internal resources back at the office. In that case, a VPN connection to the home office is common. Then you can direct access to the 3CX server via the VPN.
 
  • Like
Reactions: Enrique_Enaitech
I mean you could, but realistically in today's world of Zero Trust (and not perimeter based security like using a VPN) you really shouldn't. Not to mention the pain of connecting a VPN on your cell phone to use the 3CX mobile app (for anything besides voice, i.e. for status, chat, etc) - either it's always on, sucking battery or it's on-demand and you have to deal with those downsides.

IIRC, the recent 3CX compromise can be tied back to a VPN - an employees home PC had a VPN connection back to the office and that allowed the attackers to move laterally once inside the PC.

We've eliminated 90% of VPNs (a few management plane VPNs exist), so it is possible. We have yet to have a 3CX install compromised (knocks on wood).
 
  • Like
Reactions: Enrique_Enaitech
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,973
Messages
590,074
Members
164,893
Latest member
jbergeon