Solved Inbound SMS / MMS WITHOUT opening HTTPS 443/5001 globally?

Status
Not open for further replies.

neurocis

Customer
Advanced Certified
Joined
Oct 26, 2021
Messages
13
Reaction score
5
Is it documented anywhere what the 3CX SMS/MMS gateway servers IP address ranges are so that I do not have to open up ports 443/5001 globally? This is a restriction of our security policy but without a global rule no SMS/MMS messages flow inbound from our VoIP provider, sending is fine.

Thanks.

EDIT: I have found a couple 107.178.x.x IPs so far, but would love to know all of them officially.
 
Last edited:
I'm afraid that we do not have a list of static IPs or FQDNs as these may change at any moment without warning. That said, you could of course monitor the traffic a bit to determine which IPs are reaching your HTTPS port, as it seems you have already done, and work off that. However, this might end up being hard to manage over time especially if we're talking about multiple installations with this setup as you would need to update all instances of this configuration each time a change that affects you occurs.
 
Now that I am circling back to this, this is such an easy thing to provide which immensely increases the security of an installation. I had a friend try and DDoS my 3cx and I have to say it did not take much effort at all, I would rather not globally expose its web services when a solution is oh so trivial.
 
EDITED:

Now that I am circling back to this, this is such an easy thing to provide which immensely increases the security of an installation.

As previously mentioned, I'm afraid this is not possible. We cannot provide a static list of destinations/sources one of the reasons being the utilization of Google's App engine which renders it almost impossible due to it's dynamic nature.
 
Last edited:
  • Like
Reactions: Evolute IT
Thanks, you actually just answered all that is needed to resolve this ... " utilization of Google's App engine " ... whos address space can be found and firewall configured to just open that up to port 443/5001. That is 1000% better than opening things up globally:

https://stackoverflow.com/questions/11149470/google-app-engine-list-of-ip-addresses

I also see there are scripts which can automate the updating of the ranges! Cheers!
 
  • Like
Reactions: ChrisC_3CX
Glad to hear you found this information useful! Thank you for sharing your solution!

For anyone else reading this, I just want to add that 3CX's official recommendation is to keep inbound traffic to the https port unrestricted to ensure normal functionality of 3CX's operations as the infrastructure used may change at any moment without warning. Whether or not you will proceed with implementing these types of security methods anyway is of course your choice.
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet