- Joined
- Nov 19, 2024
- Messages
- 1
- Reaction score
- 0
Hi all,
How are others out there configuring 3CX instances to comply with UK Cyber Essentials requirements?
Specifically with external access to the webclient, CE requirements state that MFA must be used or rate limiting/throttling to block failed attempts.
With the MFA component, whilst you can use SSO with Google/Microsoft to achieve that, you can still authenticate as the user with their 3CX credentials - that can be protected by 3CX's inbuilt MFA, but it's a lot of work to get all users enrolled in that when they're not using it and instead using SSO.
It would be ideal if you could disable the inbuilt authentication for SSO'ed accounts, but I can't see a way to achieve that.
With the rate limiting, the Cyber Essentials requirements are quite specific about requiring you to block a minimum of 10 failed logins over a 5 minute period, before then locking that account for a finite period. The anti-hacking components of 3CX partly cover this, but not completely.
I've got a test system set to 5 for the "Failed authentication protection" field and the default of 4000 packets for the "Red" Security barrier, but in testing it seems to take 11 failed attempts on the web UI to get put on the black list, and that's over a very short period of time (under a minute).
Maybe it's not 11 failed attempts and instead a combination of the green/amber/red barriers and the internal protection algorithms?
Any thoughts, opinions and ideas would be welcomed
Ashley
How are others out there configuring 3CX instances to comply with UK Cyber Essentials requirements?
Specifically with external access to the webclient, CE requirements state that MFA must be used or rate limiting/throttling to block failed attempts.
With the MFA component, whilst you can use SSO with Google/Microsoft to achieve that, you can still authenticate as the user with their 3CX credentials - that can be protected by 3CX's inbuilt MFA, but it's a lot of work to get all users enrolled in that when they're not using it and instead using SSO.
It would be ideal if you could disable the inbuilt authentication for SSO'ed accounts, but I can't see a way to achieve that.
With the rate limiting, the Cyber Essentials requirements are quite specific about requiring you to block a minimum of 10 failed logins over a 5 minute period, before then locking that account for a finite period. The anti-hacking components of 3CX partly cover this, but not completely.
I've got a test system set to 5 for the "Failed authentication protection" field and the default of 4000 packets for the "Red" Security barrier, but in testing it seems to take 11 failed attempts on the web UI to get put on the black list, and that's over a very short period of time (under a minute).
Maybe it's not 11 failed attempts and instead a combination of the green/amber/red barriers and the internal protection algorithms?
Any thoughts, opinions and ideas would be welcomed
Ashley