How many blocked IPs can we save?

Status
Not open for further replies.

VoIPTools

3CX MVP
Platinum Partner
Advanced Certified
Joined
Feb 13, 2013
Messages
3,845
Reaction score
1,913
At one time there was a limit of 100 entries in the blacklist. Is that still the case? What is the limit?
 
Seeing a lot of activity from 5.62.x.x.?

I am.
 
Just checked one of our and it is at 163 at the moment so there isn't a cap of 100.
I am seeing a lot of action from 5.62.x.x as well. I attempted to blacklist the entire scope but apparently didn't do it correctly because many of the individual IPs have shown up blocked since then.
 
Hah, well we're over 500 IPs now and counting, so I think the limit is either removed or very high.

(We have the blacklist time set very high).

I am seeing a lot of action from 5.62.x.x as well.

Yes, we have a couple of pages of those ranges, thank goodness for 3CX inbuilt blocking!
 
Here is my idea. I wonder what you guys think about this....

We (VoIPTools) build a small service that copies all blocked IP addresses you have entered within 3CX up to a cloud-based central repository of questionable IP addresses. This repository keeps track of how many submissions (individual 3CX servers) have submitted the same IP address. The more submissions from different 3CX servers, the higher the ranking is for an IP addresses.

In addition to submitting IP address to the list, the service could also download a list of questionable IP addresses from the central repository. As the 3CX implementer, you choose how aggressively you want to block questionable IP addresses (High, Medium, Low, Off). The service would then update your 3CX server(s) blacklist using the call control API. To minimize the number of entries, we could flag ranges of IP addresses.

If you determine that an IP address was placed on the list in error, you could submit a removal request (much the way we do with spam listings). Or you could simply put the IP on your 3CX server's white list.

The goal is to quickly respond to questionable IP addresses by polling the collective experience of all the 3CX servers around the world. (By the way we are in over 85 countries now). We already have a robust cloud infrastructure running on Azure to host the repository.

While it would be possible to update your local list in real-time, you might choose to update the list on a schedule (Day, Hour, Minutes, Real-time).

Ideas / Thoughts / Suggestions?
 
Here is my idea. I wonder what you guys think about this....

We (VoIPTools) build a small service that copies all blocked IP addresses you have entered within 3CX up to a cloud-based central repository of questionable IP addresses. This repository keeps track of how many submissions (individual 3CX servers) have submitted the same IP address. The more submissions from different 3CX servers, the higher the ranking is for an IP addresses.

In addition to submitting IP address to the list, the service could also download a list of questionable IP addresses from the central repository. As the 3CX implementer, you choose how aggressively you want to block questionable IP addresses (High, Medium, Low, Off). The service would then update your 3CX server(s) blacklist using the call control API. To minimize the number of entries, we could flag ranges of IP addresses.

If you determine that an IP address was placed on the list in error, you could submit a removal request (much the way we do with spam listings). Or you could simply put the IP on your 3CX server's white list.

The goal is to quickly respond to questionable IP addresses by polling the collective experience of all the 3CX servers around the world. (By the way we are in over 85 countries now). We already have a robust cloud infrastructure running on Azure to host the repository.

While it would be possible to update your local list in real-time, you might choose to update the list on a schedule (Day, Hour, Minutes, Real-time).

Ideas / Thoughts / Suggestions?
--------------------------------------------------------------------------------------------------------------------------------------

I love this idea.
I've been trying to do it myself.
As an MSP, we have many customers with Hosted 3CX and we need to easily update all of their IP Blacklist in real-time.
This past weekend seemed to be a Hacker Blitz and all of our systems were sytematically being attacked by what I assume are Bots.
Although the Security Protocol seemed to catch them, too many atttempts like this act like a DDOS and I wish for more options.


Platinum 3CX Partner
 
Just checked one of our and it is at 163 at the moment so there isn't a cap of 100.
I am seeing a lot of action from 5.62.x.x as well. I attempted to blacklist the entire scope but apparently didn't do it correctly because many of the individual IPs have shown up blocked since then.
-------------------------------------------------------------------------------------------------------------------------------
I have been blocking the entire Subnet
I enter and IP Range of 5.0.0.0 and a Subnet of 255.0.0.0
Then block it until some date after my demise and save.
 
Here is my idea. I wonder what you guys think about this....

We (VoIPTools) build a small service that copies all blocked IP addresses you have entered within 3CX up to a cloud-based central repository of questionable IP addresses. This repository keeps track of how many submissions (individual 3CX servers) have submitted the same IP address. The more submissions from different 3CX servers, the higher the ranking is for an IP addresses.

In addition to submitting IP address to the list, the service could also download a list of questionable IP addresses from the central repository. As the 3CX implementer, you choose how aggressively you want to block questionable IP addresses (High, Medium, Low, Off). The service would then update your 3CX server(s) blacklist using the call control API. To minimize the number of entries, we could flag ranges of IP addresses.

If you determine that an IP address was placed on the list in error, you could submit a removal request (much the way we do with spam listings). Or you could simply put the IP on your 3CX server's white list.

The goal is to quickly respond to questionable IP addresses by polling the collective experience of all the 3CX servers around the world. (By the way we are in over 85 countries now). We already have a robust cloud infrastructure running on Azure to host the repository.

While it would be possible to update your local list in real-time, you might choose to update the list on a schedule (Day, Hour, Minutes, Real-time).

Ideas / Thoughts / Suggestions?

This. This is what I was after when I posted in the idea section.

UTM moving to PBX's is a fantastic idea.

Count me in. What kind of help can I provide?
 
Last edited:
-------------------------------------------------------------------------------------------------------------------------------
I have been blocking the entire Subnet
I enter and IP Range of 5.0.0.0 and a Subnet of 255.0.0.0
Then block it until some date after my demise and save.


After a bit of investigating, it appears that "some" of that range 5.62.X.X is a VPN provider called Privax (the parent company of Hide My Ass! http://hidemyass.com) They seem to be UK based but these IP's appear resolve all over the world. Some in the US, some in the Czech Republic, etc.

So far, I've seen:
5.62.57.X
5.62.58.X
5.62.59.X
5.62.60.X
5.62.63.X

All belong to Privax. So far.
 
I need to be a little careful not to misuse my participation in the 3CX forums, so perhaps this is not the ideal place to have this discussion? I'll add a project to our VoIPTools Ideas page (brand new) and we can carry on a more detailed conversation about design ideas there... https://www.voiptools.com/ideas/
 
  • Like
Reactions: pact
It would be a Best Practice to block from your firewall/router, and not bog down your 3cx server!
 
I have always felt it is a Best Practice to put 3CX behind a "real" firewall (never just Windows firewall). I agree blocking at the firewall would be ideal. But in some situations a very basic router might not have that capability? Also, it's not really feasible to create a clearinghouse that integrates with the zillions of firewalls out there. So if we want an automated solution, doing it at 3CX seems like the only feasible way to do a generic automated process. I'm very open to other opinions / suggestions.
 
Here is my idea. I wonder what you guys think about this....

We (VoIPTools) build a small service that copies all blocked IP addresses you have entered within 3CX up to a cloud-based central repository of questionable IP addresses. This repository keeps track of how many submissions (individual 3CX servers) have submitted the same IP address. The more submissions from different 3CX servers, the higher the ranking is for an IP addresses.

In addition to submitting IP address to the list, the service could also download a list of questionable IP addresses from the central repository. As the 3CX implementer, you choose how aggressively you want to block questionable IP addresses (High, Medium, Low, Off). The service would then update your 3CX server(s) blacklist using the call control API. To minimize the number of entries, we could flag ranges of IP addresses.

If you determine that an IP address was placed on the list in error, you could submit a removal request (much the way we do with spam listings). Or you could simply put the IP on your 3CX server's white list.

The goal is to quickly respond to questionable IP addresses by polling the collective experience of all the 3CX servers around the world. (By the way we are in over 85 countries now). We already have a robust cloud infrastructure running on Azure to host the repository.

While it would be possible to update your local list in real-time, you might choose to update the list on a schedule (Day, Hour, Minutes, Real-time).

Ideas / Thoughts / Suggestions?
Fantastic idea! We would subscribe to that service.
 
I think you may want to rethink the idea. As found on this page. 3cxacademy Slide 17
 
I think you may want to rethink the idea. As found on this page. 3cxacademy Slide 17
I respectfully disagree. While avoiding large IP ranges is mentioned, I don't think anything on that slide suggests the shared blacklist concept wouldn't be useful or workable for individual IPs - even if there are large numbers of them - if the proposed tool is designed well.
 
You know my answer.... ;)

Bruce Muir

DyCom Group
 
Hi Guys.

I've noticed hacking attempts from 5.62.x.x and I blacklisted the entire 5.62.x.x/16 subnet.

I was wondering if it would be possible or advisable as a quick work around in an instance where there is no firewall, to blacklist all other IP addresses while whitelisting only the important or required IP addresses.

What I would like to know is if this might be a solution.
 
Status
Not open for further replies.

Forum statistics

Threads
111,889
Messages
589,575
Members
164,754
Latest member
Louzan