Lots of failed authentications - how can we avoid this ?

Status
Not open for further replies.

next2

SOHO User
Basic Certified
Joined
Apr 19, 2009
Messages
53
Reaction score
0
Hi,

On our 3cx cloud instance, we see many failed authentications (and then, blacklisted IPs).
I think it would be safer to only authorize authentications coming from the 3CX tunnel and, for generic devices, from our public WAN IP address.
On the virtual server's firewall, incoming traffic on TCP 5060 and UDP 5060 is accepted only when the source is our public IP address, but we still see authentication attempts going through ...
So it means that another protocol/port is used for authentication, but which one ?

Thank you !
 
on AWS lightsail, i've completly removed 5060 rule in VM firewall as it is not possible to specify an IP restriction on lightsail, for now not seen problems.
I have only SBC and APP using 5090
 
Hello,
Additionally I would suggest to enable the Automatic Global 3CX IP Blacklist feature in your PBX from Settings / Security, so that your PBX blacklist is synced with our known list of offenders.
 
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,818
Members
164,811
Latest member
aurorasigntrtechitnet