"IP Blacklist" Heavy In September - Is There Something I Missed In Firewall Settings?

Status
Not open for further replies.

Jim.Lloyd

Free User
Basic Certified
Joined
Mar 16, 2021
Messages
55
Reaction score
15
I've had this PBX up and running since May... about 4 months. This last month (September), I have had a lot of blacklisted IPs for various authentication types: PolycomVVX, OpenVox-Wireless-Gat, Cisco SIPGateway/IOS...

Did I miss something setting up the firewall security, or have the 'bad guys' just finally scoped out my IP address? I am running all soft phones without physical phones, an SBC or bridge. I could easily do without external devices, except the soft phones.

I can't wait to get into Advanced... Something tells me the answer is in the Advanced section.

Thanks in advance for any pointers!
 
Hi Jim,

There's no hiding from them when you are on the internet, sooner or later they will scan your IP and start attempts. The fact that you see IPs being blacklisted means attempts were made, but thwarted.

You will find that attackers often launch campaigns so while you might not see anything for a while, you come in one day and find a whole bunch of IPs. It's business as usual for them, and expect this to happen from time to time.


1. Use the Automatic Global 3CX IP Blacklist in the security settings. The attempts reported by other 3CX systems quickly inform the global blacklist, so all the 3CX systems out there "look out for each other" in manner of speaking.

2. Consider modifying your firewall rules so that 5060 will only be able to talk to your trunk provider. Since you have softphones which rely on 5001 and 5090 encrypted connections by default, this should not pose a problem.

The Advanced module on security will cover this subject and give you a better understanding:
https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/
 
  • Like
Reactions: Jim.Lloyd
Putting in the firewall rule is very effective at blocking the unwanted connection attempts. The only thing you need to remember is to disable the rule when you run the Firewall Checker and enable it after the checks have been completed successfully (I forgot to do this once and it resulted in a lot of new grey hair).
 
Hi Jim,

There's no hiding from them when you are on the internet, sooner or later they will scan your IP and start attempts. The fact that you see IPs being blacklisted means attempts were made, but thwarted.

You will find that attackers often launch campaigns so while you might not see anything for a while, you come in one day and find a whole bunch of IPs. It's business as usual for them, and expect this to happen from time to time.


1. Use the Automatic Global 3CX IP Blacklist in the security settings. The attempts reported by other 3CX systems quickly inform the global blacklist, so all the 3CX systems out there "look out for each other" in manner of speaking.

2. Consider modifying your firewall rules so that 5060 will only be able to talk to your trunk provider. Since you have softphones which rely on 5001 and 5090 encrypted connections by default, this should not pose a problem.

The Advanced module on security will cover this subject and give you a better understanding:
https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/
Will do, and thank you for the detailed update!
 
Putting in the firewall rule is very effective at blocking the unwanted connection attempts. The only thing you need to remember is to disable the rule when you run the Firewall Checker and enable it after the checks have been completed successfully (I forgot to do this once and it resulted in a lot of new grey hair).
That gray hair happens soon enough, if it doesn't just fall out...(:>) I'll have to commit that to memory.
 
Status
Not open for further replies.

Forum statistics

Threads
111,977
Messages
590,094
Members
164,906
Latest member
Nari