IP attacks not blocked

Status
Not open for further replies.

xantip

Customer
Advanced Certified
Joined
Apr 24, 2012
Messages
37
Reaction score
14
Hi,

We get continuous login attemps on port 5061 of a customer, 3 tries per random internal number (both existing and non-extisting numbers).
But unsuccessful logins are not blacklisted by 3CX.

I see this in the log:
07/14/2022 10:53:37 AM - [CM102001]: Authentication failed for AuthFail Recv Req REGISTER from 192.168.15.1:56202 tid=-d87543-7640593124-1--d87543- Call-ID=e5f4a740465243e4f7a: REGISTER sip:81.83.x.x:5061 SIP/2.0 Via: SIP/2.0/TLS 45.95.147.37:56202;branch=z9hG4bK-d87543-7640593124-1--d87543-;rport=56202;received=192.168.15.1 Max-Forwards: 70 Contact: <sip:[email protected]:56202> To: <sip:[email protected]> From: <sip:[email protected]>;tag=e5f4a7404651e4f7a Call-ID: e5f4a740465243e4f7a CSeq: 2 REGISTER Expires: 3600 Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, NOTIFY, MESSAGE, SUBSCRIBE, INFO Proxy-Authorization: Digest username="119",realm="3CXPhoneSystem",nonce="414d535962cfd99137:21824e751e89f8f71c062cac983b1f31",uri="sip:81.83.x.x:5061",response="28d465ed8a113100940eea503f3857b7",algorithm=MD5 User-Agent: 3CX Phone System Content-Length: 0 ; Reason: Credentials don't match, check that authorization-ID and password match the ones in extension settings
07/14/2022 10:53:37 AM - Authetification failed: SI Recv Req REGISTER from 192.168.15.1:56202 tid=-d87543-7640593124-1--d87543- Call-ID=e5f4a740465243e4f7a: REGISTER sip:81.83.x.x:5061 SIP/2.0 Via: SIP/2.0/TLS 45.95.147.37:56202;branch=z9hG4bK-d87543-7640593124-1--d87543-;rport=56202;received=192.168.15.1 Max-Forwards: 70 Contact: <sip:[email protected]:56202> To: <sip:[email protected]> From: <sip:[email protected]>;tag=e5f4a7404651e4f7a Call-ID: e5f4a740465243e4f7a CSeq: 2 REGISTER Expires: 3600 Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, NOTIFY, MESSAGE, SUBSCRIBE, INFO Proxy-Authorization: Digest username="119",realm="3CXPhoneSystem",nonce="414d535962cfd99137:21824e751e89f8f71c062cac983b1f31",uri="sip:81.83.x.x:5061",response="28d465ed8a113100940eea503f3857b7",algorithm=MD5 User-Agent: 3CX Phone System Content-Length: 0

The attacking ip is 45.95.147.37 to 3CX on 81.83.x.x (I removed part of the external IP address of the customer). Firewall is 192.168.15.1.
This happens almost any second.

Currently I blocked the IP 45.95.147.37 on the main firewall, but I would expect 3CX automatically blacklists this IP.
Somebody any idea why this is not happening? Anti-hacking is enabled with default settings, except "Blacklist time interval" which is set to the maximum of 999999999.

Jos
 
Hello,
As we see from the events you pasted the Source IP is your firewall IP, this means the PBX does not see the real source IP for those packets.
Can you check whether you have a NAT Masquerade option enabled on firewall/router, and disable it if that's the case please? as the PBX should be able to see real source IP for external traffic to function correctly.
 
  • Like
Reactions: N_G
Hi Pierre,

All of my customers use NAT and have a lot of blacklisted IP's, but this is the only one behind a Fortigate.
Is this a specific Fortigate setting/issue?
 
Status
Not open for further replies.

Latest Posts

Members Online Now

Forum statistics

Threads
111,832
Messages
589,278
Members
164,662
Latest member
DejanMDS