- Joined
- Jul 16, 2020
- Messages
- 10
- Reaction score
- 3
Hello All,
We find a client in what I believe to be an "odd" situation in that their Management Console is locked out.
They have what I deem to be "standard" security settings for Anti-Hacking (v16 instance) and they have Console restrictions set to 3 specific, unique and ISP independent IP addresses.
But at the moment, attempts to access the Management Console from all three of these allowed IPs results in a " Login access denied. Too many incorrect login attempts. Try later or contact the Administrator." message. In addition to the "admin" account, they have two extensions with full "Allow access to 3CX Management Console" ability yet both of these extensions get the same error when trying to log in to the MC from the IP addresses on the allowed list.
So it seems at the moment they've lost complete access to the Management Console, which is find somewhat bewildering. They can access the Webclient without issue and currently all other functions and services are operating as normal it seems.
If "someone" is attempting to break the "admin" password from an IP address not in the approved access list, would that attempt be hitting the blacklist or simply "dropped" as not being from an allowed IP, assuming of course that is what is happening and is what has caused the lock out?
And even if that was being attempted and blocked by the blacklist, why would this then lock out the other "allowed" IPs and deny access to the other extensions that have this permission\right?
If this is a blacklist issue, and the "attack" is sustained, in theory there is no way to gain access again. An attack on one user from a non-approved IP should not lockout the others in my mind especially when those sign in attempts are coming from IPs on the approved list.
I guess they are going to have to wait until later\tomorrow and try again to hope that the black list timeout has passed and restores access but I am somewhat concerned about this.
Thanks in advance for any further advice.
David.
We find a client in what I believe to be an "odd" situation in that their Management Console is locked out.
They have what I deem to be "standard" security settings for Anti-Hacking (v16 instance) and they have Console restrictions set to 3 specific, unique and ISP independent IP addresses.
But at the moment, attempts to access the Management Console from all three of these allowed IPs results in a " Login access denied. Too many incorrect login attempts. Try later or contact the Administrator." message. In addition to the "admin" account, they have two extensions with full "Allow access to 3CX Management Console" ability yet both of these extensions get the same error when trying to log in to the MC from the IP addresses on the allowed list.
So it seems at the moment they've lost complete access to the Management Console, which is find somewhat bewildering. They can access the Webclient without issue and currently all other functions and services are operating as normal it seems.
If "someone" is attempting to break the "admin" password from an IP address not in the approved access list, would that attempt be hitting the blacklist or simply "dropped" as not being from an allowed IP, assuming of course that is what is happening and is what has caused the lock out?
And even if that was being attempted and blocked by the blacklist, why would this then lock out the other "allowed" IPs and deny access to the other extensions that have this permission\right?
If this is a blacklist issue, and the "attack" is sustained, in theory there is no way to gain access again. An attack on one user from a non-approved IP should not lockout the others in my mind especially when those sign in attempts are coming from IPs on the approved list.
I guess they are going to have to wait until later\tomorrow and try again to hope that the black list timeout has passed and restores access but I am somewhat concerned about this.
Thanks in advance for any further advice.
David.