- Joined
- Jun 20, 2018
- Messages
- 4,423
- Reaction score
- 2,153
I found https://www.3cx.com/docs/secure-sip/#h.o0mhxbtegc1n which mentions the legacy app has options to set: "In Management Console, go to the extension's “Phone Provisioning” tab > “Network” section to set the options “SIP Transport” to “TLS” and optionally “RTP Mode” to “Only Secure”. Just restart the app as there is no need to update settings on the 3CX app itself."
As we have a couple staff that prefer their ol' familiar interface, I did that late last week, and let them know. Today the first of those logged in after being logged out all weekend, and 3CX immediately blacklisted his IP. It was removed from the blacklist, he deleted his account out of the program, and reprovisioned using his config file. 7 hours later it happened again. At that point we noticed it was logging:
SIP request (REGISTER) from x.x.x.x was rejected. Reason: Block WAN requests is ON.
...even though he was presented with a password failure message. This error is of course from "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)." Is unchecking hat supposed to be required for Windows Client to use a secure connection?
Did it reprovision from the (I think?) original config file because that was the original insecure method, and if so why would that be allowed for 7 hours?
As we have a couple staff that prefer their ol' familiar interface, I did that late last week, and let them know. Today the first of those logged in after being logged out all weekend, and 3CX immediately blacklisted his IP. It was removed from the blacklist, he deleted his account out of the program, and reprovisioned using his config file. 7 hours later it happened again. At that point we noticed it was logging:
SIP request (REGISTER) from x.x.x.x was rejected. Reason: Block WAN requests is ON.
...even though he was presented with a password failure message. This error is of course from "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)." Is unchecking hat supposed to be required for Windows Client to use a secure connection?
Did it reprovision from the (I think?) original config file because that was the original insecure method, and if so why would that be allowed for 7 hours?