IP Addresses to whitelist for Firewall Check

Status
Not open for further replies.

kaiserh

Bronze Partner
Advanced Certified
Joined
Aug 24, 2020
Messages
28
Reaction score
5
I have a client who wishes to lock down their firewall and restrict access to 3CX.
I need to be able to complete the firewall check, so was wondering if there is a list of IP addresses I can whitelist?

When I run the firewall check, at the start it says:
  • resolving 'stun-au.3cx.com'... done
  • resolving 'stun2.3cx.com'... done
  • resolving 'stun3.3cx.com'... done
  • resolving 'sip-alg-detector.3cx.com'... done
When I look up the hostnames I get the following:
% host stun-au.3cx.com
stun-au.3cx.com has address 54.39.188.188
stun-au.3cx.com has address 54.39.179.240
stun-au.3cx.com has address 139.180.162.85

% host stun2.3cx.com
stun2.3cx.com has address 54.39.179.240

% host stun3.3cx.com
stun3.3cx.com has address 147.135.193.83

% host sip-alg-detector.3cx.com
sip-alg-detector.3cx.com has address 34.141.156.185

Are there potentially any more IP addresses, or IP address ranges, that I need to whitelist to successfully complete the firewall check?
 
  • Like
Reactions: ambor
Hello,
This is some other port's you have to whitelist
https://www.3cx.com/docs/ports/

You should maybe do the whitelist by domaine name (if you can) so if an IP change you will not have any issue.
 
It's incredible that this question keeps getting asked over the years and still no answer. 3CX should do something like Cloudflare does (https://www.cloudflare.com/ips/) or Microsoft (https://learn.microsoft.com/en-us/m...rls-and-ip-address-ranges?view=o365-worldwide)... this would allow much better Firewall configurations since you could open the ports only from the approved addresses. At the moment, you open the ports and everyone on earth has access through the Firewall which just leaves the 3CX server as the last line of defense.
 
  • Like
Reactions: cpe90
Open the firewall, run the check, close the firewall? That's my official advice.

For those who know there is no problem but can't run the checker, and they need the red to go away, all I can say is the green checkmark is just flag in the DB. If you're that advanced, you know what to do. And if not, run the firewall checker.
 
  • Like
Reactions: N_G
If 3CX would share a list of IP as mentioned by @ambor we could properly limit i.e. SIP inbound traffic from our SIP providers and those IPs used by 3CX checkers, this way we can re-run the firewall check at any time and get a green mark without messing with the database.

I could well imagine that if 3CX support gets involved in a case and discovers manual edits in the PostgreSQL database that they could actually flat out refuse any further assistance until the system has been re-deployed and cleared from unsupported modifications and thus brought back to a known "support-able" state. (While I've not experienced this with 3CX, I've been walking that thin line with otehr vendors of Linux-based appliances with limited shell access.)
 
These are the IP addresses that I know so far being used by the Firewall Check:

51.79.116.90
54.39.75.88
54.39.179.240

FYI, it kept changing every time you ran the firewall check.

Maybe others can add more to the list after they run the firewall check so we have a good list of IP addresses to whitelist?
Just a thought.
 
These are the IP addresses that I know so far being used by the Firewall Check:

51.79.116.90
54.39.75.88
54.39.179.240

FYI, it kept changing every time you ran the firewall check.

Maybe others can add more to the list after they run the firewall check so we have a good list of IP addresses to whitelist?
Just a thought.
This one did it for me: 151.80.120.125

Regards,
Mike
 
The list of IPs keeps changing and part of the test is to receive a reply from an IP the request was not sent to so those IPs also keep changing.
The purpose of the firewall checker is to make sure that you have configured the firewall correctly and all necessary ports are open. Once you do this and you successfully pass the test then lock down your firewall to the IPs you know and trust.

However if something goes wrong and you suspect it's a firewall issue then you need to take the firewall back to a state where the firewall checker passes and see if the issue persists in that configuration. This is what 3CX support wants.

The firewall checker is meant to give you a reference point for your configuration so you have everything you need open and a point to revert if you have any issues.
 
  • Like
Reactions: VoIPTools
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet