Hi Felicia,
I will try to address you concerns below.
3CX moved a bunch of their hosting resources last week. They moved them to Italy.
All 3CX online services run in large Hosting Providers. I have double-checked and no changes or moves have been made recently.
I know this does not answer your "
then why did it happen?" question, but at least you can rule out this possible cause.
I wish that 3CX would actually either know their own infrastructure better, or publish a list of FQDNs and IP ranges the way that Microsoft does.
We have this information publicly available in our Academy page:
https://www.3cx.com/3cxacademy/videos/basic/installing/
(Slide 10)
This information would also be happily provided to you if you had contacted our Support Team as well.
The actual 3CX server may try to contact other online resources, but this will be due to other configurations of the OS.
The PBX also has certain hardcoded features like sets of time servers that it wants to talk to on the internet rather than using an NTP source that you provide or even being efficient about finding an NTP source within the same country as the PBX.
That's the worst one. It wants to talk to NTP sources all over.
The PBX software itself for NTP uses the time server configured on the OS, whatever that is. You may however have spotted in Settings --> Parameters, a parameter called "TIME_NTP_SERVER" which contains the value pool.ntp.org.
I can see how some may think this is what the PBX uses, but that would wrong. This value is passed onto the phones via their Provisioning Template, so
the phones (not the PBX) use this NTP.
Having said this, feel free to change this to any other NTP server you want and reprovision your phones, then the phones will use the NTP you have defined.
But I do know that 3CX defaults also did not match their security requirements.
Penetration testing that I did when I was first evaluating the PBX revealed that phones could be hacked with SIP Vicious from external connections when using the 3CX recommended network rules.
We as 3CX extensively pen test and stress test our software constantly in between releases and before releasing a new Update. If you have found any potential vulnerabilities that directly affect the
PBX software, then I would suggest you to open a Support Ticket with our Support Team and the information you give us will be analyzed, verified and sent to the Dev Team if indeed there is some vulnerability.
We also collaborate with a number of IP Phone manufacturers. We do also run some pen tests on these devices and report any findings to the vendors. It should be noted though that the main pen testing on IP Phones devices is done by the IP Phone manufacturers, who in turn help create the template we end up bundling with our software. Likewise, if you have found any vulnerabilities with specific IP Phones, you can either contact the manufacturer directly, or again, open a Support Ticket with your findings, which will be analyzed, verified and sent to the corresponding manufacturer, with which we have a good working relationship (with the Support IP Phones).
I wish that 3CX would hire a network security architect that would help them flush out these issues and get resolutions in place for them.
I will just boil this suggestion down to your frustration with the issue you were facing.
