CHANGING SIP PORT IN PBX EXPRESS

Status
Not open for further replies.

SPB

Free User
Joined
Apr 22, 2020
Messages
5
Reaction score
1
Hi, I install in the google cloud a PBX Instance for test purpose. This is working great but i dont change the default sip port (5060). Now I want to change it. On your forum, i read i have to reinstall the pbx to change the sip port. I deleted the pbx from my google cloud account and reinstall from your website: https://pbxexpress.3cx.com. I enter my 3cx key and they do the install but i can access to the first time configuration utility, So my PBX its working again with my initial FQDN but i can change the SIP port.

Thank you
 
It would appear that you can not change the SIP port on the express version,

Any reason why you want to change the port number ?
 
Thank you for your quick answer! I just want to change then for security reason. I have some random attack but the PBX blacklist the IP. I cant close the 5060 port on my google firewall because i have old sip device and they not supported by my SBC. Maybee i can try port redirection ex.: external port 5091 to internal port 5060 and let external 5090 to internal 5090 for my SBC and IOS devices.
 
It's called PBX Express for a reason. You're one of those people that tries to customize their order at a fast food place and makes the rest of us wait aren't you :)

If you just want it to work and you don't know or care about what happens under the hood you use PBX Express. If you want to do something other than what it wants, you use do a ISO/manual install
 
Thank you for your quick answer! I just want to change then for security reason. I have some random attack but the PBX blacklist the IP

This does not make it any more secure, any hacker worth his keyboard is scanning more than just the default sip port number.

99% chance your old device will work fine with the SBC, you just need to configure it manually, configure it as if it is connecting directly to the 3CX server, except swap out the FQDN/IP of the 3CX server with the IP address of the SBC, leave everything else as it normally would be.
 
99% chance your old device will work fine with the SBC, you just need to configure it manually, configure it as if it is connecting directly to the 3CX server, except swap out the FQDN/IP of the 3CX server with the IP address of the SBC, leave everything else as it normally would be.

I will try that thank you very much ! I will let you know if it works.
 
Indeed changing the SIP port will not help much, because hackers tend to scan multiple ports for services. You will see IPs being blacklisted regardless of whether you change the port or not.

If it works with the SBC then you can use the public IP as the registrar and the SBC IP as the proxy (which is how we provision modern phones) otherwise like Brentt said use the SBC IP directly and do some testing.

By the way, 5060 is not just used by remote phones, so if you close it down entirely you will probably lose access to your trunk provider too. One solution would be to modify your firewall to allow 5060 but only from known IPs.
 
I will try that thank you very much ! I will let you know if it works.
This does not make it any more secure, any hacker worth his keyboard is scanning more than just the default sip port number.

99% chance your old device will work fine with the SBC, you just need to configure it manually, configure it as if it is connecting directly to the 3CX server, except swap out the FQDN/IP of the 3CX server with the IP address of the SBC, leave everything else as it normally would be.

Its working ! I put the local IP of my SBC in the old device.
Thank you
 
  • Like
Reactions: BrenttG
As more time passes, infected machines all over the globe are running port scans of 65,534 ports (both TCP and UDP), and the scans are becoming more and more sophisticated. Since computers don't get bored, distributed attacks target chunks of IP addresses and scan ranges of ports. Simply moving to a different port is a type of Security Through Obscurity, but it's not really protecting much.
 
  • Like
Reactions: BrenttG
As long as you can see the IPs being blacklisted, that means that the PBX is going it's job of protecting itself and fending off the "Attackers".

What we would recommend is to enable the 3CX Global IP Blocklist and 3CX will take care of the scans. We gather these IPs from your Block List and when we see a trend, enter these IPs into the Global list and distribute these to all the PBXs with the option enabled.

I would also increase the Blocklist interval to 1,000,000,000 seconds (yes, that's a BILLION, and without the commas). This equates to 11574 days approximately, which is 31.7 years.

Like a Boeing engineer once said, when the JT9D engine of the original 747 stops leaking oil, that's when you should start worrying. likewise, when these emails stop, that's when you should start worrying!
 
  • Love
Reactions: BrenttG
As more time passes, infected machines all over the globe are running port scans of 65,534 ports (both TCP and UDP), and the scans are becoming more and more sophisticated. Since computers don't get bored, distributed attacks target chunks of IP addresses and scan ranges of ports. Simply moving to a different port is a type of Security Through Obscurity, but it's not really protecting much.
Perhaps you are right , but having some PBX with non standard 5060 port used for SIP and those pbxs are not having their blacklist increasing every day.
on others using 5060 they are restricted to SIP provider IP and global blacklist is enabled on all
 
As more time passes, infected machines all over the globe are running port scans of 65,534 ports (both TCP and UDP), and the scans are becoming more and more sophisticated. Since computers don't get bored, distributed attacks target chunks of IP addresses and scan ranges of ports. Simply moving to a different port is a type of Security Through Obscurity, but it's not really protecting much.

So many people tell me I am wrong about this it is really sad, they truly believe by changing the ports for a given service(SIP, RDP, others) to some completely random number in the high range, that they are totally secure and only people who know the number can get in, and they think a port scan is just a password guessing script, and do not understand even the basics of how flawed their understanding is.
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK