- Joined
- Feb 1, 2021
- Messages
- 5
- Reaction score
- 3
Dear All,
I have been reading the threads pertaining to Blacklisted IPs but couldn't find one relating to my issue.
Almost every morning when work resumes at my office, I received an email pointing out that IP w.x.y.z has been blacklisted on PBX myownpbx.3cx.com
From IP records, I know this is one of our 100 employees. Furthermore Geo IP localisation online tool, indicates that the IP is inside my organistaion. Unfortunately, the Event Log with its ID do not provide much information to trace it out.
I have launched a wireshark capture (verbose enabled) and let it run. The problem with that method is that I need not to overfill the log partition if I forgot to stop it and it appears like a fisherman catching a fish. The idea was to parse the captured pcap traces with the command sip.CSeq.method == REGISTER to see if there is any relevant info regarding a particular account. From there on, contact the user and sort out the issues.
Is there anyone onboard who has a better idea to trace out that blacklisted user please?
Also note that I have unchecked Global Blacklist option. I have checked that IP range in Blacklist and it was now there. Besides that other users do connect on that same subnet w.x.y...
Thanks all for your help.
I have been reading the threads pertaining to Blacklisted IPs but couldn't find one relating to my issue.
Almost every morning when work resumes at my office, I received an email pointing out that IP w.x.y.z has been blacklisted on PBX myownpbx.3cx.com
From IP records, I know this is one of our 100 employees. Furthermore Geo IP localisation online tool, indicates that the IP is inside my organistaion. Unfortunately, the Event Log with its ID do not provide much information to trace it out.
I have launched a wireshark capture (verbose enabled) and let it run. The problem with that method is that I need not to overfill the log partition if I forgot to stop it and it appears like a fisherman catching a fish. The idea was to parse the captured pcap traces with the command sip.CSeq.method == REGISTER to see if there is any relevant info regarding a particular account. From there on, contact the user and sort out the issues.
Is there anyone onboard who has a better idea to trace out that blacklisted user please?
Also note that I have unchecked Global Blacklist option. I have checked that IP range in Blacklist and it was now there. Besides that other users do connect on that same subnet w.x.y...
Thanks all for your help.
