Firewall Whitelist & Media QoS FQDN List - Can I use for firewalling Audio Dial In bridge?

Status
Not open for further replies.

richardatncp

Free User
Joined
Aug 27, 2020
Messages
14
Reaction score
0
As the thread subject says;

There is a sticky thread entitled " Firewall Whitelist & Media QoS FQDN List". In it there is a list of FQDNs relating to the web conferencing service.

I have used this list on my firewall to restrict traffic related to web conference audio dial in.

Am i correct to use this list for that purpose or am i inadvertly excluding some hosts?

Thanks,
 
Hi Richard,

The list helps you whitelist the FQDNs so that Webmeeting just works. And by "works" that includes dial in users too.

Some background details: the PBX has a webmeeting bridge which does exactly this job - connect dial in users that speak with the PBX, to the webmeeting servers that exist in the cloud and run independent to your PBX. You also need to make sure that the 3CX firewall checker also passes so that the audio ports of your instance can talk to the aforementioned servers.
 
It fails the firewall test with inbound SIP allowed only for these servers, but the audio dial in does work for the few tests i have tried.
Is the 3CX firewall test server not in this list (presume not)?
 
The firewall tester does not check anything related to webmeeting
 
This doesnt answer my original question on correctly firewalling webmeeting audio dial in.

I can't find any information on the technical aspects of how audio dial in works for webmeetings, but my guess is as follows:
participant dials internal or external conf number and is asked for the PIN. if this passes then a control messaged is sent from 3CX to the web conferencing service telling it to make a SIP call into our 3CX.
What i dont know is that if the origin of these SIP calls is only from the FQDN list in the message sticky thread or can come from other IP addresses.

My simple tests so far have worked with firewall rules applied, but i might have got 'lucky'.
 
Hi Richard,

I have used this list on my firewall to restrict traffic related to web conference audio dial in.

Am i correct to use this list for that purpose or am i inadvertly excluding some hosts?

Just for clarification:
If I understood you correctly, you meant "allow" in place of "restrict"?
Because restrict would imply that you restricting/blocking the traffic from reaching you = no webmeeting
 
The firewall rule is set to only permit inbound SIP traffic to 3CX from the FQDNs listed in addition to the SIP trunks
 
Ok then it should be correct for your purpose.
 
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,078
Members
164,896
Latest member
sameage