Limit Direct SIP to Certain IPs

Status
Not open for further replies.

vbreyter

SOHO User
Joined
May 20, 2020
Messages
10
Reaction score
1
Is there a way to restrict Direct SIP calls to certain IPs? We are hosting 3CX on AWS and phones are directly connecting to the 3CX server. So we cannot use a firewall to restrict port 5060 access since phones are connecting from changing IP addresses. We also have a Twilio app that we need to be able to initiate Direct SIP connections to the 3CX server. The Twilio IPs are static so we would like to restrict the Direct SIP ability to just the Twilio IPs.

Note: we already looked at the Twilio SIP Domain functionality and it doesn't work for us. We would have to have each phone connect directly to Twilio instead of (or in addition to) the 3CX server which doesn't work for us. We also cannot add a separate Twilio SIP trunk for each phone as that becomes unmanageable.
 
Is there a way to restrict Direct SIP calls to certain IPs?
Do you mean from certain IPs to your server IP? If that is the case, then you would need to use a firewall. However, as you have extensions connecting from outside your locals LAN, you would obviously have to be selective about which IPs were permitted and which were blocked unless your extensions were configured to use the the 3CX tunnel. So if it were certain IPs, then, yes, you could block them with a firewall. If it were all IPs except valid registrations, then it gets a bit trickier.
 
It's the latter unfortunately. I need to whitelist which IPs 3CX will accept Direct SIP calls from, but at the same time, I need to leave the SIP Port open since the extensions that are connecting have dynamic IPs. That's why I don't think a firewall solution works. I was hoping that 3CX would have a functionality whereby it would only accept Direct SIP calls from a whitelist of IPs, or other mechanisms. Right now all I can find is just a binary, either Direct SIP is enabled or it's not.
 
While 3CX does have an IP Blacklist, with the ability to Whitelist as well, it is not meant to replace a comprehensive firewall. If there is no way of knowing which IP, or range, your extensions are going to use to register, then how can you expect to blacklist a wide range of IPs?

https://www.3cx.com/docs/allow-deny-ip-addresses/
 
Again the idea would be not to blacklist or whitelist IPs as a general matter. But to only accept Direct SIP requests from particular IPs.Is there no way to separate access control for the registration functionality (which is protected via username/pw) from the Direct SIP functionality?

Since the extensions are connecting from IPS provided dynamic IPs there is no way to create a whitelist for these IPs. Even if I could collect all the ISP ranges for each IPS provider, a worker can always change to a different ISP.
 
I don't know of anyway of doing that, but someone else, may have some ideas.
 
The answer is no. You have two options:

- Make all our remote phones into remote apps/webclient or configure them to use a VPN and block SIP at the firewall.
- Leave it open to all and let 3CX blacklist do it's job.

You don't actually mention what the use case is or what you are afraid of happening. Elaborating on either/both would help craft a possible solution, although I think you are overthinking things in this case.
 
  • Like
Reactions: nub
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,964
Messages
590,000
Members
164,869
Latest member
hpgitsupport