Limiting Web Access to only 3CX FQDN

Status
Not open for further replies.

tomatobees

Free User
Joined
Apr 6, 2019
Messages
3
Reaction score
0
I have an installation that is failing a PCI scan from the WAN. The PCI scan is scanning by WAN IP address. When the scan hits port 5001, the scan sees an invalid certificate because the cert is registered to the fqdn of the 3CX server (me.state.3cx.us). If you hit the server with the fqdn, the cert is valid. How do I prevent the 3CX server from responding to anything but the fqdn?
3CX is V16 running on 3CXs version of Debian Linux.

Thank You,
 
Since this is not a 3CX concern you aren't really going to find any answers here. There is a way to do it but that involves editing files that 3CX won't support. So let's be smart about this. First of all, 3CX should be part of your CDE so if it is, you have a bigger problem there. Move it out of your CDE and then no worries. Otherwise, just plug the PCI scan source IP on your firewall so it doesn't see 3CX. Or just turn off the web service, run the scan and call it a day. The fact that it listens on IP isn't a security issue.

If really insist on doing it the hard way then go over to the nginx forums and ask there since the webserver 3CX uses is nginx and you'll get much better answers there.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,918
Messages
589,738
Members
164,793
Latest member
Sense-IT-Mike