Intrusion attempt blocking solutions that don't break the firewall checker?

Status
Not open for further replies.

jcayer

Customer
Basic Certified
Joined
Jun 25, 2019
Messages
33
Reaction score
7
I've been having a significant amount of random intrusions being attempted in my deployed PBXs. They are all the latest version v.16 and are all on-premises. I can see in the logs multiple attempts with different user agents "Avaya", "Linksys SPA942", etc.. all trying different extensions "100" "12345" "100000" "201" etc.. Of course after the offending IP has tried over 20 times, it gets blacklisted for a day and it quiets down.

This keeps freaking me out. I figured I could modify my port forwarding rules to only allow 5060 "from" our SIP provider's IP range or actual addresses. This would completely shut down the hacking attempts at a firewall level before it even hits 3CX. In practice, calls still work fine and I feel like we're safer. 1 caveat though: The firewall checker is upset that 5060 isn't fully open any more. Does anyone else have any suggestions to help in this situation? I was thinking if I could figure out what IP or range the checker uses, I could just whitelist that to solve the problem? that may just open it wide up again though. LOL.
 
first you can set and reduce failed login tries from 20 to 3 for example.
You can enable global blacklist if not done.
If you don't use phones out pbx location, then you can just set your firewall for 5060 to your sip provider only. It's not a problem if Firewall checker is red but everything works and of course you know why red.
 
  • Like
Reactions: JohnS_3CX
We have this exact same sort of issue, we do block globally 5060 (since it is such a well known port for SIP) and only allow from certain known IP addresses.

You could try a custom port for SIP instead perhaps, or as stated above globally blacklist all IP ranges and whitelist known/trusted IP's instead.
 
  • Like
Reactions: JohnS_3CX
Hi @jcayer

You can try enabling the global black list first and see how it goes.

Settings > Security > Automatic Global 3CX IP Blacklist

If the attackers have tried to hack into other 3CX systems, there is a good chance their IPs are already included in the blacklist.
 
On top of all this I would also (for further precaution in the event a hacker does breach the PBX) restrict the PBX to only the country codes which are required, and also restrict the outbound rules.

The outbound rules can be altered so that calls are only from your known extension ranges, extension groups and only to number types (length and prefix you specify).

If a hacker did gain access they often will try high premium number calls and run a bill up with a dodgy provider they are in cahoots with.
 
  • Like
Reactions: JohnS_3CX
Thanks to everyone who responded!

Summary of my input on the suggestions:
  1. Yes, I have the 3CX blacklist enabled. That's a really cool option, but didn't seem to make too much of a difference. Its nice to know I'm helping others though by submitting.
  2. I may try reducing the failed attempts from 20 or 25 to 10. That adds a little security.
  3. Yes, I did lock-down 5060 to only my SIP provider's IP range. This quiets it down nicely. It's nice to hear that even though the firewall checker is red, there's no real issue otherwise. Strangely enough, I was just watching the 3CX advanced training video on security and they actually state that you should block SIP traffic from everywhere BUT your sip provider at your firewall. Funny that no mention of the firewall checker is made in that video. :)
  4. Changing the SIP port is an option I suppose, but I haven't tried it yet.
  5. Restricting the PBX to country codes required: Big YES! Great backup protection, but I want to stop them before they get there. Heh.
  6. Modifying outbound rules to limit by known extensions: Great idea, but I really don't want them in there in the 1st place.

Hopefully this helps everyone add a little security to their system. Thanks again!
 
number 4 is a last resort if at all, as if you are not strong in your networking understanding, you may have difficulties getting your stuff to use the alternate port if it doesnt have a 3CX prefab template. Also, changing the port number will fool the dumb bots, but there are plenty of smarter bots that actually fingerprint the port range slowly over time, and they will find the sip port and other ports even if they are re-mapped. Your only outwitting the lazy bots.
 
A couple of notes:

1. In case you have issues you can reopen 5060 to run the checker, and close it later if need be. Ultimately, the SIP port must be open to those that need to reach it (i.e remote STUN phones) but there ways around it. The new mobile clients use 5090 so no harm there, the Webclient uses 5001 and desktop client can use 5090 with tunnel also

2. SIP ports are defined during setup only, you would have to reinstall if you wish to change it!
 
the Webclient uses 5001

This has been up for debate previously, as you can see here: https://www.3cx.com/docs/ports/ and I would like to see this updated for web client specifically as this is pretty much what 99% of our customers use now.

5060 - Remote Extensions that are NOT using the 3CX Tunnel Protocol, web client does not use the tunnel to my knowledge, so what ports are required for web client ?

We only use STUN phones for single remote users now also, too much firewall hassle required when dealing with 3rd party management of FW.
 
It connects to the PBX on 5001 and the RTP media range
 
Right!! that makes sense Web RTC works with UDP and has no standard signalling protocol.
 
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,818
Members
164,811
Latest member
aurorasigntrtechitnet