I am seeing a lot of action from 5.62.x.x as well.
--------------------------------------------------------------------------------------------------------------------------------------Here is my idea. I wonder what you guys think about this....
We (VoIPTools) build a small service that copies all blocked IP addresses you have entered within 3CX up to a cloud-based central repository of questionable IP addresses. This repository keeps track of how many submissions (individual 3CX servers) have submitted the same IP address. The more submissions from different 3CX servers, the higher the ranking is for an IP addresses.
In addition to submitting IP address to the list, the service could also download a list of questionable IP addresses from the central repository. As the 3CX implementer, you choose how aggressively you want to block questionable IP addresses (High, Medium, Low, Off). The service would then update your 3CX server(s) blacklist using the call control API. To minimize the number of entries, we could flag ranges of IP addresses.
If you determine that an IP address was placed on the list in error, you could submit a removal request (much the way we do with spam listings). Or you could simply put the IP on your 3CX server's white list.
The goal is to quickly respond to questionable IP addresses by polling the collective experience of all the 3CX servers around the world. (By the way we are in over 85 countries now). We already have a robust cloud infrastructure running on Azure to host the repository.
While it would be possible to update your local list in real-time, you might choose to update the list on a schedule (Day, Hour, Minutes, Real-time).
Ideas / Thoughts / Suggestions?
-------------------------------------------------------------------------------------------------------------------------------Just checked one of our and it is at 163 at the moment so there isn't a cap of 100.
I am seeing a lot of action from 5.62.x.x as well. I attempted to blacklist the entire scope but apparently didn't do it correctly because many of the individual IPs have shown up blocked since then.
Here is my idea. I wonder what you guys think about this....
We (VoIPTools) build a small service that copies all blocked IP addresses you have entered within 3CX up to a cloud-based central repository of questionable IP addresses. This repository keeps track of how many submissions (individual 3CX servers) have submitted the same IP address. The more submissions from different 3CX servers, the higher the ranking is for an IP addresses.
In addition to submitting IP address to the list, the service could also download a list of questionable IP addresses from the central repository. As the 3CX implementer, you choose how aggressively you want to block questionable IP addresses (High, Medium, Low, Off). The service would then update your 3CX server(s) blacklist using the call control API. To minimize the number of entries, we could flag ranges of IP addresses.
If you determine that an IP address was placed on the list in error, you could submit a removal request (much the way we do with spam listings). Or you could simply put the IP on your 3CX server's white list.
The goal is to quickly respond to questionable IP addresses by polling the collective experience of all the 3CX servers around the world. (By the way we are in over 85 countries now). We already have a robust cloud infrastructure running on Azure to host the repository.
While it would be possible to update your local list in real-time, you might choose to update the list on a schedule (Day, Hour, Minutes, Real-time).
Ideas / Thoughts / Suggestions?
-------------------------------------------------------------------------------------------------------------------------------
I have been blocking the entire Subnet
I enter and IP Range of 5.0.0.0 and a Subnet of 255.0.0.0
Then block it until some date after my demise and save.
Fantastic idea! We would subscribe to that service.Here is my idea. I wonder what you guys think about this....
We (VoIPTools) build a small service that copies all blocked IP addresses you have entered within 3CX up to a cloud-based central repository of questionable IP addresses. This repository keeps track of how many submissions (individual 3CX servers) have submitted the same IP address. The more submissions from different 3CX servers, the higher the ranking is for an IP addresses.
In addition to submitting IP address to the list, the service could also download a list of questionable IP addresses from the central repository. As the 3CX implementer, you choose how aggressively you want to block questionable IP addresses (High, Medium, Low, Off). The service would then update your 3CX server(s) blacklist using the call control API. To minimize the number of entries, we could flag ranges of IP addresses.
If you determine that an IP address was placed on the list in error, you could submit a removal request (much the way we do with spam listings). Or you could simply put the IP on your 3CX server's white list.
The goal is to quickly respond to questionable IP addresses by polling the collective experience of all the 3CX servers around the world. (By the way we are in over 85 countries now). We already have a robust cloud infrastructure running on Azure to host the repository.
While it would be possible to update your local list in real-time, you might choose to update the list on a schedule (Day, Hour, Minutes, Real-time).
Ideas / Thoughts / Suggestions?
I respectfully disagree. While avoiding large IP ranges is mentioned, I don't think anything on that slide suggests the shared blacklist concept wouldn't be useful or workable for individual IPs - even if there are large numbers of them - if the proposed tool is designed well.I think you may want to rethink the idea. As found on this page. 3cxacademy Slide 17
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.