Console restrictions in V16

Status
Not open for further replies.

GPO

Free User
Basic Certified
Joined
Mar 6, 2019
Messages
15
Reaction score
0
In a previous post discussing security concerns it was stated that it was safe to now allow 5001 presence information (and by the looks of it contacts too?) to be opened for all as it was possible to restrict console access to specific IP addresses. I've now taken a look at the console restriction settings but unfortunately it automatically adds all private IP address ranges and allows no changes, this means that I cannot block the internal NAT address for my firewall.

This security feature does not seem as useful as I first thought, as if you are behind a NAT then the IP address is always a private one, any reason why it was decided to automatically allow all private addresses?
 
Hi GPO

It's useful for blocking access from external unknown IPs. The console is still protected with 3 failed login attempts however, regardless of where the connection comes from and will ban anyone that attempts to log in whether via LAN or WAN ranges.

If you manage the customer's PBX remotely for example and only allow your office public IP to access the MC but your internet goes down what would happen? You also lose access to the MC permanently and there's no way into the system by legitimate users such as yourself. This is avoided by trusting the private IP network, which if we did not include automatically would mean that you are locked out.
 
I do understand the scenario that you paint, however in my situation there is an IT department onsite so that would not be an issue. I have been asked to make sure that there is no management access except from the local LAN, so I wonder if this is hard coded in software or is there a config file or registry entry I can change to achieve this? Worst case scenario we can deploy with vastly reduced functionality which whilst it would not sell the product well internally, it would not risk stopping the roll out.
 
This is hard coded as seen below, and turning it on will achieve the desired result that they have asked for.

Simply turning the feature while using a local PC and accessing the MC using the PBX's private IP will allow you to achieve this.

For example in this installation below, the local PC 10.31.0.59 connected to the management console's local IP and enabled the feature. All the IPs seen here are local and the system is locked down to only accept console connections from here based on what the NIC is bound to in this environment, effectively making the MC accessible only internally:

10939


The highlighted blue IP is already within the 1.0.0.0/8 range so anyone one the internal network is effectively whitelisted to the log in screen.
 
  • Like
Reactions: Fulforce
Sorry, but either I've missed your point or you've missed mine!

Internet ClientFirewall Ext IFPort ForwardFirewall Int IF3CX Server
82.132.231.6186.34.191.1905001<>10.100.0.60172.30.100.2510.100.0.60

In the example above, 3CX server sees a request made by 82.132.231.61 or any other public IP as coming from 172.30.100.25, and allows it as it's in the allow list 172.16.0.0/12.
 
This only happens if you set your firewall to replace both the source and destination IP in your incoming incoming packets. In this way, yes you defeat the purpose of the feature completely. But why would your firewall be replacing the source IP?

Does the 3CX Firewall Check pass?
 
NATting is in place as a) it's our suppliers standard procedure and b) there is a lot of network in-between the server and the public internet. This would not be an issue if we were talking about a small organisation with everything at one location, my installation is in a data centre in a large organisation with 130 sites and an internal private WAN. We have no public SIP connections so the firewall check fails on that point.

Edit: I'll ask the FW maintainer if they can change the NAT to being a destination NAT rather than source.
 
Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,928
Messages
589,771
Members
164,799
Latest member
RicoDinero