- Joined
- Feb 16, 2022
- Messages
- 10
- Reaction score
- 2
I have received an email alert to say a given IP address "has made numerous attempts to authenticate with 3CX with invalid details. In response, 3CX has created a blacklist rule denying this IP to continue sending requests."
Wonderful, though that same email says that blacklist entry "will expire on: Monday, 28 February 2022 16:04:12". which has now passed.
I look up the IP and I am happy it is malicious so I want to make sure it is always blacklisted - so I try to add it to the IP Blacklist.
Even though that IP address is NOT in my blacklist, when I try to add it I get the error "This IP address is already in the blacklist"
I now understand that IP address may be in the 3CX Global Blacklist described at https://www.3cx.com/blog/voip-howto/global-ip-blacklist/ which is fine.
Here are my questions / points:
> If we get an alert like this the email should SAY it is in the Global Blacklist rather than my local install blacklist.
> Is there a 3CX Global Blacklist Lookup so I can verify the IP really is in that blacklist and when it is really going to expire?
> If that IP 'drops off' the 3CX blacklist, then it looks like we could be exposed again. I want to add it myself but I can't. Do we wait to be exposed before we can tighten things up?
I think this needs some work.
Wonderful, though that same email says that blacklist entry "will expire on: Monday, 28 February 2022 16:04:12". which has now passed.
I look up the IP and I am happy it is malicious so I want to make sure it is always blacklisted - so I try to add it to the IP Blacklist.
Even though that IP address is NOT in my blacklist, when I try to add it I get the error "This IP address is already in the blacklist"
I now understand that IP address may be in the 3CX Global Blacklist described at https://www.3cx.com/blog/voip-howto/global-ip-blacklist/ which is fine.
Here are my questions / points:
> If we get an alert like this the email should SAY it is in the Global Blacklist rather than my local install blacklist.
> Is there a 3CX Global Blacklist Lookup so I can verify the IP really is in that blacklist and when it is really going to expire?
> If that IP 'drops off' the 3CX blacklist, then it looks like we could be exposed again. I want to add it myself but I can't. Do we wait to be exposed before we can tighten things up?
I think this needs some work.