IP Blacklist on 3CX

Status
Not open for further replies.

nickmcg2727

New User
Joined
May 20, 2024
Messages
7
Reaction score
0
Hi,

We are looking at switching to 3CX, but it appears the IP blacklisting is too aggressive. I found out the hard way by configuring a Yealink handset with old firmware. However, this lockout behavior is the same for end users, if someone or two people happen to type in the wrong password up to 10 times or I suppose 5 times each, it will lockout their office IP address for 24 hours.

A lot of people are posting about this issue in these forums over the last year, we know in the Pro/Enterprise version you can add IP address exceptions, when is 3CX going to extend this functionality to SMB Pro? You could at least put the lockout time to 15-30mins or something smaller.

This is not a business ready product; we both know end users will keep trying and lockout the office IP address - or is it 3CX's intention to make SMB Pro inconvenient so we will buy the more expensive Pro/Ent subscription? If so, we'll look at other products and not bother with 3CX.

Thanks.
 
The blacklist is triggered after failed attempts to login.
This can be expected as a way to disallow any unauthorized access that can cause other issues. For the SMB solutions the blacklist is not available and you can contact 3CX Support via ticket or wait for 24 hours for the blacklist to be auto-removed.
 
@TheodorosG_3CX that's not the point. Users will blacklist their office IP address for 24 hours, you know this, users will keep retrying. When is 3CX going to add the blacklist exceptions to the SMB Pro subscription?

Second point - I know why you do it, but why does it need to be 24 hours? Why not 15 minutes?
 
For the SMB the blacklist will not be available.
The 24 hours blacklist is part of the security design in the 3CX SMB Installations and this cannot be changed for the SMB.
 
That's not acceptable for a small business to have their internet connection blacklisted by 3CX for 24 hours. Given the other feedback on other threads, when is this going to be reviewed?
 
Folks, Under Security there Blacklisted Numbers https://pbx-fdqn.3cx.co.uk/#/app/settings/number_blacklist where admins can either add individual numbers or bulk upload. This is what I'm referring to and am floating the request/option to be able to control this at the SIP trunk or department level.

I think you're getting confused with Blacklisted IPs.
No, not number blacklist - IP address blacklist.

So, if a user or a couple of users type their password incorrectly, the 3CX SMB Pro hosted instance will blacklist the offices internet connection, therefore blocking the entire office for 24 hours. I don't think 3CX have thought this one through properly.
 
SMB is a shared platform and the blacklist is at the server level. So allowing an IP would allow it for any other account on that server. Someone could allow their IP and guess your extension passwords without limit.

The alternative is a Pro license which has more control.
 
Blocking further login attempts after a reasonable number of failed attempts is a pretty basic security feature. We do not want hackers trying to brute-force passwords. What I think you are really looking for is the ability for an Administrator to manually reset the account after addressing the user's password issue. That seems like a reasonable feature request.
 
  • Like
Reactions: Evolute IT
@SteveITS @VoIPTools I get where you guys are coming from, and I already understood this is necessary. The point is, deterrent from brute force attacks isn't blacklisting every IP address for 24 hours that has 10 attempts. This is the current security policy and could be an end user or multiple end users within a small business. 10 attempts is not a brute force attack.

Without any big scripting changes, working within these parameters of time vs attempt for the entire hosted 3CX instance, they could block an IP address after 10 attempts for 30mins and then unblock, then block again if it continues. There's 24 hours (1440 mins) divide by that's 48 unblocks, by 10 attempts - that's 480 attempts in 24 hours. That's hardly a brute force attack. If 3CX security team pick up on this continuing to happen after x days and x attempts, then block the IP address.

If a business has their email or passwords compromised to the point someone knows and attempts to guess their 3CX password (not brute force), that business has bigger issues. @TheodorosG_3CX thoughts?
 
@nickmcg2727 I've brought attention of our security team to this matter.
 
@ivank any luck with the security team? I'm trying to implement SMB at a customer site and configure one of their Yealink phone handsets, but the phone is causing the lockout for 24 hours. This time I tried auto provisioning.

Either way, it's quite annoying because I have tried 3 times now and end up getting blacklisted for 24 hours because the phone tries again up to 10 times and blacklists the customers IP address. Even an end user or a couple of end users could try in the wrong password 10 times.
 
@ivank any luck with the security team? I'm trying to implement SMB at a customer site and configure one of their Yealink phone handsets, but the phone is causing the lockout for 24 hours. This time I tried auto provisioning.

Either way, it's quite annoying because I have tried 3 times now and end up getting blacklisted for 24 hours because the phone tries again up to 10 times and blacklists the customers IP address. Even an end user or a couple of end users could try in the wrong password 10 times.
You need to use an SBC or Routerphone. Please read the requierements
 
  • Like
Reactions: bitn2
This is also clarified in the guideline:
1717469773622.png
 
  • Like
Reactions: PaulC_3CX and bitn2
Same issue with me today when configuring phones. Someone also posted about it over here https://www.3cx.com/community/threads/upgraded-to-pro-no-change-ip-blocked.127631/#post-606171

And it has been raised numerous times in the past. @TheodorosG_3CX it's not a great experience from a business perspective, when is the policy changing? It would be more suitable blacklisting IP addresses after 50-100 attempts for 1 hour, that would be considered a brute-force attack, not 10 attempts. If the 3CX security team cannot not detect when a brute-force attack is occurring, then we have bigger issues.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,283
Members
164,662
Latest member
DejanMDS