Encryption on legacy Windows Client

Status
Not open for further replies.

SteveITS

3CX MVP
Silver Partner
Advanced Certified
Joined
Jun 20, 2018
Messages
4,423
Reaction score
2,153
I found https://www.3cx.com/docs/secure-sip/#h.o0mhxbtegc1n which mentions the legacy app has options to set: "In Management Console, go to the extension's “Phone Provisioning” tab > “Network” section to set the options “SIP Transport” to “TLS” and optionally “RTP Mode” to “Only Secure”. Just restart the app as there is no need to update settings on the 3CX app itself."

As we have a couple staff that prefer their ol' familiar interface, I did that late last week, and let them know. Today the first of those logged in after being logged out all weekend, and 3CX immediately blacklisted his IP. It was removed from the blacklist, he deleted his account out of the program, and reprovisioned using his config file. 7 hours later it happened again. At that point we noticed it was logging:

SIP request (REGISTER) from x.x.x.x was rejected. Reason: Block WAN requests is ON.

...even though he was presented with a password failure message. This error is of course from "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)." Is unchecking hat supposed to be required for Windows Client to use a secure connection?

Did it reprovision from the (I think?) original config file because that was the original insecure method, and if so why would that be allowed for 7 hours?
 
Hi Steve,

The app has the 3CX tunnel function - this get's bypassed/disabled and the app is trying to connect directly to the server's SIP port because you chose to use TLS mode.

The "Disallow use of extension outside the LAN" option will now hence apply since you are not coming in via the tunnel. If access was blocked, it will fail to register and probably end up blacklisted for failed attempts. So you can either use the tunnel OR use SIP TLS on this app, but certainly not both at the same time.

We recommend you update the users to our new app since the old one will not work forever and they will have to switch eventually. On the new app, everything is encrypted by default, you don't have a choice and you cannot turn off encryption.
 
OK thank you for confirming. That checkbox may be a good idea to add to the doc page.

Agree on changing to the new app but some people don't like change. :)

Still strange it let him use it for several hours.
 
I noticed that the lock disappeared in the 3CX application during calls, which confirmed that the traffic on the 3cx tunnel was encrypted. Now the lock icon has disappeared. why?

and the second question: Is text correspondence via the 3cx application also encrypted?
 
Because there is no longer any differentiation, everything is encrypted by default whether it is chat or voice.

We do not recommend you use the older app any more as it is no longer being developed so do not expect it to change its behavior with regards to functionality or icons and such.

Switching to the new app will you can be certain that all the traffic is TLS.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,973
Messages
590,075
Members
164,895
Latest member
jasonkkrause