Cloudflare DNS Proxy

Status
Not open for further replies.

Owen

Forum User
Joined
Sep 7, 2017
Messages
9
Reaction score
6
I see a fairly constant stream of attempts from all over the world to log into my PBX hosted in AWS.

I was thinking of 'putting' it behind a Cloudflare DNS Proxy - is this a very bad idea? The public facing IP would change fairly frequently I believe, so this is my main concern, currently.

Has anyone tried this or have a better suggestion?

What does everyone else do to reduce these 'hacking' attempts?
 
I doubt you are seeing attempts to login to the PBX interface. More than likely you are seeing SIP attempts. But you either trust 3CX is secure or you don't. CloudFlare proxy would stop script kiddies but wouldn't fool anyone who knows what they are doing. Keep 3CX updated, have a strong admin password and enable the global blacklist
 
Cloudflare would also alter the templates for provisioning as they pass thru its proxy, and you would have to add a lot of page rules to add exceptions to make it stop, plus your sip ports cannot pass thru, so you would have to edit templates manually to match up ports properly, just don't do it, your in for more headache than its worth, i looked into it once before myself.

There is a way to utilize a reverse proxy to make it happen, but its a mess....
 
Ok, thank you very much for your replies - yes you're right, it's just SIP requests. I have a complex username and password and the global blacklist enabled already. I have also set the lockout rules very 'tightly'. So I will just leave it as is and hope for the best :)
 
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,921
Members
164,851
Latest member
DrunkeMeister