Increase in blacklisted IP addresses

Status
Not open for further replies.

Mark Phillips

Customer
Advanced Certified
Joined
Jan 28, 2019
Messages
154
Reaction score
53
Normally I get very few blacklisted IP addresses (presumably most are dealt with by the internal blacklist), however in the last 48 hours, I've had about 30 IP addresses added to my blacklist. The User Agent on all is stated as 3CXPhoneSystem.

Anyone else?
 
Yes, yesterday I had about 15 added to the blacklist. User agent is 3CXPhoneSystem as well.
 
User agent means nothing , it's most surely a fake agent name
 
Hi Mark,

Attackers use a fake user agent. They think that if they pretend to be something they're not that they will somehow be granted access, but your system blocked them. They can put anything they want in the user agent, it's just a SIP field
 
I've had about 30 IP addresses added to my blacklist
change your 5060 nat to forward only to sip provider IP, this can be done if you don't use phones out of LAN, App are not concerned as they use 5090.
This give you a red firewall checker if you execute it after this change, but do nothing for PBX abilities
 
Yes, I realise the User Agent is easily faked - it's just the first time I've seen 3CXPhoneSystem used.

Good suggestion to block 5060 to everything except SIP trunk
 
  • Like
Reactions: AWS2P
Yes, I realise the User Agent is easily faked - it's just the first time I've seen 3CXPhoneSystem used.

Good suggestion to block 5060 to everything except SIP trunk

Ensure you are not using any remote STUN phones though, as they will not be able to contact the PBX on 5060. Any users using our apps / SBC-based phones will not be affected since they go via tunnel
 
This guide suggests that 5060 is UDP only. However, looking at a router configuration guide, it suggests TCP and UDP is required. Can anyone confirm?

Also, I think I should also lock the RTP ports down to the IP address of the SIP trunk? But unlike port 5060, which only needs to route to the PBX, I think the RTP ports need to be able to route to any of the VoIP devices on the LAN - otherwise the PBX will have to handle all of the incoming audio. Is that right?
 
if you want your Pbx working fine but with no audio , lock RTP ports :p:).
 
That's not what I asked. I want to confirm whether I should only permit RTP traffic originating from the SIP Trunk?
 
Hi Mark,

Follow this specifically, it explains what and why: https://www.3cx.com/docs/ports/

Also what does "permit RTP traffic originating from the SIP Trunk" mean?
Use more descriptive terms like:
  • Incoming traffic from Provider IP to PBX IP
  • Outgoing traffic from PBX IP to Provider IP

Just note that even though your PBX might LISTEN for audio at 9000-10999, it may TALK to the provider at any range they ask for. Depending on what you meant above, you may end up blocking outgoing traffic to the range your provider wants and you will have incoming audio working fine but outgoing audio not working as expected
 
Hi John
Okay, using your terminology:

Do I need to allow incoming RTP traffic from:

  1. SIP provider to PBX IP only
  2. SiP provider to PBX IP and network VLAN where VoIP devices reside

I think it is 2 but please confirm.
Thanks
Mark
 
Hi Mark,

Let's clarify then:

1. SIP provider to PBX IP only - this is incoming direction traffic, you would want to limit it to 5060+RTP Range, to keep the baddies out :)

2. the vlan where the devices reside - the devices only talk to the PBX, not the provider. the PBX delivers the audio to them internally so they don't have to be exposed to the outside world. I'm assuming you are talking about a local PBX here
 
Hi John
Okay, thanks for the clarity. I think where my confusion has crept in is the "PBX delivers audio" option - which currently I have ON for the trunk, but OFF on all extensions (which all reside within the same LAN).

If my understanding is correct then:

  • An external call (i.e. via the SIP trunk) will ALWAYS have RTP audio routed via the PBX
  • An internal call (i.e. between two extensions on the LAN) will route RTP audio directly to each other, bypassing the PBX
 
Hi Mark,

That is correct with an exception on point 2 for internal calls:

The phones have to be Local or SBC to exchange audio between them (they are on the same network).
The call recording feature needs to be off (otherwise PBX will forcefully deliver audio in order to record)
 
  • Like
Reactions: Mark Phillips
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,819
Members
164,811
Latest member
aurorasigntrtechitnet