- Joined
- Apr 6, 2020
- Messages
- 35
- Reaction score
- 14
We've started using 3CX in May 2020 and in July we started getting IP blacklisting notification mails. The amount of IPs being blacklisted has increased since then and over 200 IPs were blacklisted during the last three weeks.
I already increased the blacklisting time from the inital 1 day to 30 days in July.
The blacklisting notifications all look the same except for the user agent:
I'm starting to get worried and would like to block these brute force login attempts. Do these blocked login attempts only occur on port 5060?
I guess I should be able to restrict access to this port to our SIP providers IP address. Though I'd need to check that all of our remote clients use the 3CX Tunnel Protocol (Smartphone Apps and Windows Clients).
Any thoughts or pointers on this? Is this a common problem? How do others tackle this?
Some additional information about our System:
Kind regards and stay safe everyone!
Karl
I already increased the blacklisting time from the inital 1 day to 30 days in July.
The blacklisting notifications all look the same except for the user agent:
The IP 45.141.156.19 on PBX [REDACTED] has been blacklisted and will expire on: 2021/01/16 09:19:17.
Affected Module: SIP Server
User agent: PolycomVVX-VVX_300-UA/4.1.6.4835
Reason: Too many failed authentications!
This IP Address 45.141.156.19 has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.
No action is required on your behalf.
Affected Module: SIP Server
User agent: PolycomVVX-VVX_300-UA/4.1.6.4835
Reason: Too many failed authentications!
This IP Address 45.141.156.19 has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.
No action is required on your behalf.
I'm starting to get worried and would like to block these brute force login attempts. Do these blocked login attempts only occur on port 5060?
I guess I should be able to restrict access to this port to our SIP providers IP address. Though I'd need to check that all of our remote clients use the 3CX Tunnel Protocol (Smartphone Apps and Windows Clients).
Any thoughts or pointers on this? Is this a common problem? How do others tackle this?
Some additional information about our System:
- 3CX Version: Professional Annual 16.0.1078
- Server OS: Debian Hyper-V image provided by 3CX
- Is the 3CX Server Hosted and where?: Hosted on premises
- Has the Firewall Checker passed: YES
Kind regards and stay safe everyone!
Karl


