Continuous Attack from Different IP Add

Status
Not open for further replies.
You have identified the ports but it shows all ip's. This is not an improvement. You need too restrict the allowed IP to you trunk provider(s).
 
You have identified the ports but it shows all ip's. This is not an improvement. You need too restrict the allowed IP to you trunk provider(s).
Thats true... you need to restrict port 5060 to the subnet from your provider to get rid of this attacks.
 
You need to be on Hosted by 3CX - clearly you dont have the experience to run a PBX on the cloud. Or work with a partner that provides hosting.
 
  • Like
Reactions: JamieR
You need to be on Hosted by 3CX - clearly you dont have the experience to run a PBX on the cloud.
This would be the best solution in this situation.
 
  • Like
Reactions: N_G
have you tried a 'who is' lookup on those IP's?
 
Even with your config you will continue to have bots absolutely spank your box on port 5060.
Who is your SIP provider? They should have a published list of IP addresses that they send traffic from unless you have a register trunk, in which case you can close 5060 altogether.
 
For what... doesnt matter where this ips are from.
- yeah, - I was curious enough to have a look just now... - finding Who is actually there might be a challenging job.....
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,278
Members
164,662
Latest member
DejanMDS