- Joined
- Mar 7, 2023
- Messages
- 78
- Reaction score
- 19
Is anyone else getting this threat warning from your firewall?
We are using Palo Alto FW, and this port has been hit constantly by bad actors trying to expose IOT devices.
https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/
This port is only required if we use SIP Trunk / VOIP Provider, but I do not think we need it if we are hosting it on-premise.
But the 3CX firewall check will fail if we don't allow this inbound UDP port.

I'm curious to see what others are doing in your on-prem environment.
Do you let the 3CX firewall check to fail by not opening the ports, or do you still allow them even though you're not using them and ignoring the firewall threat warning for the sake of passing the 3CX firewall test?
And also, I wish 3CX would tell us from what IP this firewall check is coming from because they used IP addresses from all over the world and I'm only allowing US-based connections so most of the time the firewall test will fail anyway.
Thank you, guys, for your feedback.
We are using Palo Alto FW, and this port has been hit constantly by bad actors trying to expose IOT devices.
https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/
This port is only required if we use SIP Trunk / VOIP Provider, but I do not think we need it if we are hosting it on-premise.
But the 3CX firewall check will fail if we don't allow this inbound UDP port.

I'm curious to see what others are doing in your on-prem environment.
Do you let the 3CX firewall check to fail by not opening the ports, or do you still allow them even though you're not using them and ignoring the firewall threat warning for the sake of passing the 3CX firewall test?
And also, I wish 3CX would tell us from what IP this firewall check is coming from because they used IP addresses from all over the world and I'm only allowing US-based connections so most of the time the firewall test will fail anyway.
Thank you, guys, for your feedback.