- Joined
- Jun 25, 2019
- Messages
- 33
- Reaction score
- 7
I've been having a significant amount of random intrusions being attempted in my deployed PBXs. They are all the latest version v.16 and are all on-premises. I can see in the logs multiple attempts with different user agents "Avaya", "Linksys SPA942", etc.. all trying different extensions "100" "12345" "100000" "201" etc.. Of course after the offending IP has tried over 20 times, it gets blacklisted for a day and it quiets down.
This keeps freaking me out. I figured I could modify my port forwarding rules to only allow 5060 "from" our SIP provider's IP range or actual addresses. This would completely shut down the hacking attempts at a firewall level before it even hits 3CX. In practice, calls still work fine and I feel like we're safer. 1 caveat though: The firewall checker is upset that 5060 isn't fully open any more. Does anyone else have any suggestions to help in this situation? I was thinking if I could figure out what IP or range the checker uses, I could just whitelist that to solve the problem? that may just open it wide up again though. LOL.
This keeps freaking me out. I figured I could modify my port forwarding rules to only allow 5060 "from" our SIP provider's IP range or actual addresses. This would completely shut down the hacking attempts at a firewall level before it even hits 3CX. In practice, calls still work fine and I feel like we're safer. 1 caveat though: The firewall checker is upset that 5060 isn't fully open any more. Does anyone else have any suggestions to help in this situation? I was thinking if I could figure out what IP or range the checker uses, I could just whitelist that to solve the problem? that may just open it wide up again though. LOL.