Firewall Question on New Setup V20

Ron Gonzales

Silver Partner
Basic Certified
Joined
Mar 25, 2019
Messages
10
Reaction score
1
Hello All,

On a blank install of V20 I have reviewed the following article https://www.3cx.com/docs/manual/firewall-router-configuration/
Which leaves me with a lot of questions

1) With an On-Prem Install of 3cx should we be installing a SBC on prem to broker the incoming connections from IOS, and Adroid, windows client, and remote phones?
2) Assuming no SBC, the article gives us the ports needed but not the source IP's I'd imagine that the SIP Trunk providers could let me know their blocks but what about the Apps, Video Conf, I see other services are given the DNS name but many firewalls dont allow DNS names in their source ACL's
3) If we are installing an SBC should we forward these rules to the SBC instead?
 
1) With an On-Prem Install of 3cx should we be installing a SBC on prem to broker the incoming connections from IOS, and Adroid, windows client, and remote phones?
no
2) Assuming no SBC, the article gives us the ports needed but not the source IP's I'd imagine that the SIP Trunk providers could let me know their blocks but what about the Apps, Video Conf, I see other services are given the DNS name but many firewalls dont allow DNS names in their source ACL's
There should be no restriction on source addresses in the required port forwarding / firewall rules.
3) If we are installing an SBC should we forward these rules to the SBC instead?
no, never
 
  • Like
Reactions: Ron Gonzales
Thanks for the reply, so if there should be no restrictions on source addresses, we just leave our servers open on all ports from "ANY" traffic? Isnt that not a good idea from a securtiy perspective?
 
The SIP ports can be restricted to the provider. This will cause the firewall check to fail, but you can open them briefly for this.

HTTPS port and Tunnel ports should be open for the 3CX smartphone apps, web clients, softphone client and router phones to work. If none of this is required, then you can reconsider this.

You're basic certified - right? You should know that.
 
The SIP ports can be restricted to the provider. This will cause the firewall check to fail, but you can open them briefly for this.

HTTPS port and Tunnel ports should be open for the 3CX smartphone apps, web clients, softphone client and router phones to work. If none of this is required, then you can reconsider this.

You're basic certified - right? You should know that.
The Firewall module is part of the Advanced course!
 
The SIP ports can be restricted to the provider. This will cause the firewall check to fail, but you can open them briefly for this.

HTTPS port and Tunnel ports should be open for the 3CX smartphone apps, web clients, softphone client and router phones to work. If none of this is required, then you can reconsider this.

You're basic certified - right? You should know that.
Yup Basic certified and doing voip for a while which is why i am surprised that there wouldnt be a SBC on a DMZ segement to handle this inbound traffic in a secure way. Avaya, Mitel, and Cisco all have SBC's deployed in this manner because openeing up HTTPS to a server, espeically a windows server should be done only when you have a web app firewall etc. Maybe 3CX suggests having a seperate VOIP segment un-routable to the rest of the network because of this? In any case, thanks for the insight.
 
The Firewall module is part of the Advanced course!
But you also explain these requirements during the basic installation courses. Or have I remembered it wrong? Wait a minute - I'll look at my notes ;)
 
Thanks for the reply, so if there should be no restrictions on source addresses, we just leave our servers open on all ports from "ANY" traffic? Isnt that not a good idea from a securtiy perspective?
You should keep the HTTPS and/or Tunnel ports open from "ANY" because you could have people trying to connect via their devices from a home office, an airport, a hotel. Basically anywhere in the world.

These protocols have their own security mechanisms (the tunnel has an added layer of authentication in addition to the encryption) and HTTPS is self explanatory as it is a worldwide protocol in used for security.

The SIP Port can be limited to the provider, and this is actually a recommendation of ours, so as to prevent network scans.

Yup Basic certified and doing voip for a while which is why i am surprised that there wouldnt be a SBC on a DMZ segement to handle this inbound traffic in a secure way. Avaya, Mitel, and Cisco all have SBC's deployed in this manner because openeing up HTTPS to a server, espeically a windows server should be done only when you have a web app firewall etc. Maybe 3CX suggests having a seperate VOIP segment un-routable to the rest of the network because of this? In any case, thanks for the insight.

The PBX is essentially the SBC in this case.

The firewall essentially allows the traffic to go to the PBX only on the required ports. We have numerous security mechanisms in place to prevent breaches of the system.
 
  • Like
Reactions: Ron Gonzales
But you also explain these requirements during the basic installation courses. Or have I remembered it wrong? Wait a minute - I'll look at my notes ;)
It was part of the basic course about 4 years ago!
 
  • Haha
Reactions: fxbastler
You should keep the HTTPS and/or Tunnel ports open from "ANY" because you could have people trying to connect via their devices from a home office, an airport, a hotel. Basically anywhere in the world.

These protocols have their own security mechanisms (the tunnel has an added layer of authentication in addition to the encryption) and HTTPS is self explanatory as it is a worldwide protocol in used for security.

The SIP Port can be limited to the provider, and this is actually a recommendation of ours, so as to prevent network scans.



The PBX is essentially the SBC in this case.

The firewall essentially allows the traffic to go to the PBX only on the required ports. We have numerous security mechanisms in place to prevent breaches of the system.
Thanks for the clarification, that helps alot. I will go to my SIP provider to get the ports, and allow the remaining inbound on ANY source.
 
  • Like
Reactions: NicholasP_3CX

Forum statistics

Threads
111,954
Messages
589,923
Members
164,852
Latest member
priya