Constantly receiving "SIP request (REGISTER) from..." warnings...

Status
Not open for further replies.

Erik Nathe

Free User
Joined
Sep 22, 2017
Messages
56
Reaction score
3
For the last week I have been receiving numerous warnings in the 3CX event log that are not from us. I'm guess it's someone's malicious repeated attempts. I'm wondering if there is a way to stop them? I have blocked the IP's that show but they just keep coming from other IP's...

SIP request (REGISTER) from xx.xx.xx.xx was rejected. Reason: Block WAN requests is ON. Message: REGISTER sip:xx.xx.xx.xx SIP/2.0 Via: SIP/2.0/UDP xx.xx.xx.xx:5520;branch=z9hG4bK48e7a990-5d20-44e8-96c2-05d072e2f6c6;rport=5520;received=xx.xx.xx.xx Max-Forwards: 70 Contact: <sip:[email protected]:5520;rinstance=db9b244e6fd1994a> To: "798"<sip:[email protected]> From: "798"<sip:[email protected]>;tag=ohdecrfv Call-ID: pcasvkvqjvahnmlbpeenqwveupdvknobrhmifssolpgutdfron CSeq: 2 REGISTER Expires: 3600 Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, SUBSCRIBE, NOTIFY, REFER, INFO, MESSAGE Proxy-Authorization: Digest username="798",realm="3CXPhoneSystem",nonce="414d53596075d58f48:f6884c57abed6ae42f68b427c2ece517",response="8640338a415f0d78c3925671e2c6ee2a",uri="sip:xx.xx.xx.xx1",algorithm=MD5 Supported: 100rel User-Agent: PolycomVVX-VVX_401-UA5.4.1.18405 Content-Length: 0
 
The internet is a scary place. Turn on the 3CX global blacklist, be sure you didn't dumb down any of the security defaults in 3CX and ignore the rest.
 
I've got that on already! And I definitely haven't messed with any of the security defaults. I guess I'll just ignore them. Thanks.
 
  • Like
Reactions: NickD_3CX
I've seen the following now every 10 minutes or so: "SIP request (REGISTER) from (*********) was rejected. Reason: Block WAN requests is ON. Message: REGISTER sip"... It's now gotten ridiculous.
 
The internet is scary on Sundays too!
 
  • Haha
Reactions: NickD_3CX
Just want to add that, in regards to security, 3CX also will automatically block/ignore requests from User Agents that are known to be used in security and hacking tools. You can of course adjust the settings in "Settings >> Security" for additional hardening though, enabling the Global IP Blacklist as @cobaltit mentioned would indeed be a good first step to take. For maximum security however you might want to consider implementing security barriers on the network level such as allowing traffic from only known IPs through your firewall, provided of course that you always know which these IPs are and that they never change.
 
Status
Not open for further replies.