IPv6 Whitelist

Drain Bamaged

Premier Customer
Joined
Mar 6, 2020
Messages
68
Reaction score
18
Good Day,

We restrict 3CX admin console access by allowing only specific internal IPv4 ranges where our admins work.

After the last major update, this rule appeared under Advanced > IP Blacklist on all of our installs:

1781876711985.png

This appears to allow any internal IPv6 link-local address to access the admin console. That effectively bypasses the IPv4 restrictions we put in place.

The rule was not created by us, appears to have been added automatically, and cannot be deleted.

Can 3CX confirm why this rule exists and how it can be removed or disabled?

Thanks.
 
Hi, if you go to the advanced menu --- console restriction --- the rule for fe80::/10 is marked as allowed. These are local IPv6, note that when enabling console restriction, by default ALL local IPs are allowed including IPv6.

The console restriction feature is for blocking the admin access to external IPs, that is why you have to add static public IPs there...

Click 'Add' below to enter permitted IP Addresses. IP Addresses added here are automatically included into the IP Blacklist and set to 'Allowed'. The Link-local IPv4, Link-local IPv6, and Private IPv4 Addresses are pre-populated already and cannot be deleted
 
Hi @Alejandro_3CX

>note that when enabling console restriction, by default ALL local IPs are allowed including IPv6.

We had controls in place with internal IP whitelist to a single C Class private subnet in our HQ building. That eliminated any external access and admins had to be on that subnet exclusively. Your new rules nullify those controls and open access to any point in our internal network which is multi-national.

Your rules are wide open, undermining our much tighter restrictions and we cannot delete them. That is a security concern for us.

I checked the V20 release blogs/change history and cannot find any reference to this being advertised or documented.
 
@Drain Bamaged since the console restriction feature was added in the PBX, it allowed the access from any LOCAL LINK, beard in mind that console restriction is just to disable the ADMIN button access, meaning that only from trusted external IPs and local link you can access the admin panel. Also note that the ADMIN panel is visible for those extensions with roles higher than the USER role.

The blacklist function that is in the advanced menu is for blocking or allowing IPs to access the pbx console, sip registration, etc, so CONSOLE RESTRICTION is just to enable or disable the ADMIN button, when used it will be shown for those trusted ips that were added.
 

Forum statistics

Threads
111,818
Messages
589,167
Members
164,642
Latest member
davids86