ip blacklist

Status
Not open for further replies.

Heath

Customer
Advanced Certified
Joined
Aug 12, 2017
Messages
287
Reaction score
3
Lately I've been getting a bunch of IP addresses that have been getting on my blacklist. Friday I had 20 in that day alone in a matter of 3 hours, and just today I have another 15. These IP addresses are not mine, and most of them are out of the USA. This is unusual for me of getting so many. The reason for the blacklist is saying Too many failed authentication and the affected Module is SIP Server Call Manager. My SIP providers gave me their IP addresses to whitelist. Just checking to see if this is very unusual to be getting so many of these, and if there is an suggestions... I'm not having any issues with the system, and its running fine
 
The internet is a scary place. Obviously those aren't your IP addresses otherwise your post would say something like my phones won't register. 3CX is doing the job your firewall isn't.
 
Firstly the good news is that the PBX is doing it's job and blacklisting the IP addresses, the bad news is that you are getting what sounds like potential SIP hack attempts.

I would check the firewall in front of the PBX and see if you have any rules which expose port 5060 to "any" public address as opposed to specifics.

The only other time I have had IP blacklists is when a device such as a gateway or IP endpoint has misconfigured SIP account details but correct registrar details.

It sounds like these addresses are public so I doubt it would be this however.
 
Firstly the good news is that the PBX is doing it's job and blacklisting the IP addresses, the bad news is that you are getting what sounds like potential SIP hack attempts.

I would check the firewall in front of the PBX and see if you have any rules which expose port 5060 to "any" public address as opposed to specifics.

The only other time I have had IP blacklists is when a device such as a gateway or IP endpoint has misconfigured SIP account details but correct registrar details.

It sounds like these addresses are public so I doubt it would be this however.


I don’t believe there is anything on the firewall which probably explains all these blacklists. I believe that the firewall is open. I use a windows server in the cloud and while I’m a bit savvy of Windows 7, I’m not that savvy in windows server. If someone can give me some guidance here on how to set the firewall in windows server would be greatly appreciated. And IP address, would I set just the IP addresses on port 5060 on the SIP trunks, or would I also include the IP addresses of each location that connects to the cloud where the PBX is located.
 
I guess you don't have any control of the firewall in that case ?

If nothing has been configured specifically then it will block all by default however I would confirm with whoever the administrator is whether this is the case.

Additionally if you have a proper firewall in front of the server there is little need in my view to have the server firewall on.
 
And IP address, would I set just the IP addresses on port 5060 on the SIP trunks, or would I also include the IP addresses of each location that connects to the cloud where the PBX is located.

Do you want those locations to be able to connect to the PBX? Seems pretty self explanatory.
 
I guess you don't have any control of the firewall in that case ?

If nothing has been configured specifically then it will block all by default however I would confirm with whoever the administrator is whether this is the case.

Additionally if you have a proper firewall in front of the server there is little need in my view to have the server firewall on.


I don’t have any administrator. It’s just me and I’m not that savvy on Windows server
 
Who said anything about Windows Server? You would typically configure the firewall on your EDGE device.
 
Who said anything about Windows Server? You would typically configure the firewall on your EDGE device.


And how would I do that.
 
This doesn’t help me much. As I don’t have a separate firewall. I’m using windows server in the cloud. And I believe there is a firewall in windows server in the cloud
 
I'm just looking at hardening our server for similar reasons.

Today I blocked incoming traffic on port 5060 (tcp&udp) & 5061 (tcp) to everywhere except you providers IP address. I've yet to see how much difference that makes but I'm thinking it should sort the problem.

I've also increased the default blacklist time and if I see dodgy traffic from 2 IP addresses that start with the same first 2 dotted quads (e.g. 5.6.10.50 and 5.6.20.100) I block the range 5.6.0.0/255.255.0.0 in the 3CX blacklist. Clicking on the IP address heading in blacklist helps sort them into an order where you can tell this.

Windows server has a firewall and your VPS provider probably has one too.
 
Status
Not open for further replies.

Forum statistics

Threads
111,898
Messages
589,614
Members
164,764
Latest member
billza209