Change managment console port

Status
Not open for further replies.

greychain

Gold Partner
Advanced Certified
Joined
Jul 13, 2018
Messages
779
Reaction score
122
Our customer is worried that the management console port is exposed to the interenet .

Is there any way this port can be changed?

Why does it need to be on the same port as the provisioning/presence port ?

I've done the usual suggestions. Good password, limit failed connections, only allow managment access for known IP's. They are worried about hacking attempts.
 
Yes, console use 443 or 5001 depends on your installation , If login and password have been changed and not weak, you can add if not already done automatic global 3CX IP blacklist in security settings, set max 3 to failed authentication protection.
Let SSL enabled for SIP transport and Ciphers.
 
So can the console port be put on 443 and the other services left on 5001?
 
If you have a firewall on your side you could just do some rules to limit it if they're that worried.

You can configure the port when you configure the 3CX.

Here : https://www.3cx.com/docs/manual/configuring-your-pbx/#h.us8asarjs8i8
Step 3 - Select DNS Type and Ports
Select the ports to use for HTTP and HTTPS access to the Management Console and for VoIP services, i.e. SIP and tunnel ports. 3CX detects whether you are using NAT or not based on your IP. If you are behind a NAT you need to configure your firewall/router accordingly.

All ports being used : https://www.3cx.com/docs/ports/
 
Our customer is worried that the management console port is exposed to the interenet .

Is there any way this port can be changed?

Why does it need to be on the same port as the provisioning/presence port ?

I've done the usual suggestions. Good password, limit failed connections, only allow managment access for known IP's. They are worried about hacking attempts.

Your customer is concerned about the management port being on the internet. But, you change it and it is still on the internet....
 
  • Haha
Reactions: FS_Mathieu
I never want to speak about security with telephony but come on, if a hacker really focus on you, he will find an enter since you don't have a global security politic.

Being defended from robot attacks is a start as you did :rolleyes:
 
Our customer is worried that the management console port is exposed to the interenet .

Is there any way this port can be changed?

Why does it need to be on the same port as the provisioning/presence port ?

I've done the usual suggestions. Good password, limit failed connections, only allow managment access for known IP's. They are worried about hacking attempts.

Hi,

The management console runs on the HTTPS port along with a lot of other services as you can see here https://www.3cx.com/docs/ports/

It is not possible to make it run on another port not exposed to the internet, even if you change the port number during installation.

Security-wise this interface will lock down after a few attempts and will also not allow anyone to enter from any destination that you have excluded.

Taking it off the internet means you would lose any remote services like the webclient, webmeeting, iOS and Android apps, as well as the desktop client and any STUN phones or SBC based phones provisioning.
 
The wording of my question was not precise enough and Iwasn't clear on what I wanted to achieve. Remove internet access to the managment console, only allow it from local network. Still be able to have access to other services that also use this port.

JohnS_3CX answer makes it clear it cant be done "It is not possible to make it run on another port not exposed to the internet, even if you change the port number during installation. "

Which is the answer I need to provide to my client.

Thanks for everyones help.
 
I believe you can achieve what you need with "console restriction" built in to the security settings on 3cx.
 
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,817
Latest member
Innovative Advisory