Constant notifications of Blacklisted on PBX

Status
Not open for further replies.

Mike Shintani

Customer
Joined
May 17, 2023
Messages
38
Reaction score
3
I receive approximately 10 notifications of an IP address being blacklisted each day. Sometimes there are more in a given day. Is this normal and expected? Does this indicate I have configured something incorrectly or missed something in our Hosted 3CX setup? A redacted example is below.


The IP X.X.X.X on PBX YYYYYYY has been blacklisted and will expire on: 2023/07/26 18:12:22.
Affected Module: SIP Server
User agent: PolycomSoundPointIP-SPIP_450-UA/3.3.4.0085

Reason: Too many failed authentications!

This IP Address X.X.X.X has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.

No action is required on your behalf.

If you would like to review, edit or delete the rule, you can do so from your Management Console > Dashboard > IP Blacklist.
For more information:
https://www.3cx.com/docs/allow-deny-ip-addresses/
 
This will be common when someone tries to authenticate to the 3CX system using a device with the specified user agent. The 3CX System is doing its job of protecting you from such unauthorized access attempts, and no further action is required from your side.
 
  • Like
Reactions: Mike Shintani
If only there was a way to restrict the IP Addresses that are allowed to Port 5060 within the hosted infrastructure then this would stop this problem!! Our SIP trunk provider gives us a single specific IP address that calls will come from but I'm unaware of a way to setup a restriction.

PLEASE PLEASE PLEASE implement a way for us to restrict what IP addresses are allowed to connect on 5060 when on your hosted infrastructure (or tell me how to do it if there already is!)
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,843
Messages
589,328
Members
164,680
Latest member
JV J