Many Block WAN requests is ON warnings, is there risk of hacking?

Status
Not open for further replies.

migors

Customer
Joined
Nov 13, 2017
Messages
39
Reaction score
1
Hi friends i recently updated to v16. And i noticed that i have many warning events like below. I have 2 phones and 2 softphones and they work without problems.
is there some security problems? These ip adreses like SIP/2.0/UDP 212.83.174.223:5126 are not coming from my organization.
How can i block them? only adding to ip blacklist?
I have pro version in google cloud. In office i have mikrotik router. When i saw these warnings closed all ports in google firewall only to pbx and office addresses, but warnings continue to appear.
Thanks


P.S i replaced my ip with <myofficeip>


Code:
SIP request (REGISTER) from <myofficeip> was rejected. Reason: Block WAN requests is ON.
 Message:
 REGISTER sip:<myofficeip> SIP/2.0
 Via: SIP/2.0/UDP 212.83.174.223:5126;branch=z9hG4bK853a232c-328a-4191-beae-f626a590f7ac;rport=5126;received=88.135.145.234
 Max-Forwards: 70
 Contact: <sip:[email protected]:5126;rinstance=f63168fa797b764b>
 To: "99"<sip:99@<myofficeip>>
 From: "99"<sip:99@<myofficeip>>;tag=twbplwvb
 Call-ID: vxknmxkdwuommmbpwnmovxcjnljeidxtojeekgnfhtfvyjfatv
 CSeq: 2 REGISTER
 Expires: 3600
 Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, SUBSCRIBE, NOTIFY, REFER, INFO, MESSAGE
 Proxy-Authorization: Digest username="99",realm="3CXPhoneSystem",nonce="414d53595ca7070879:520e73d20b3d5e9c574c9d07a0d65152",response="7b4ed49f302788d4fc2e5c994a3b2094",uri="sip: <myofficeip>",algorithm=MD5
 Supported: 100rel
 User-Agent: Avaya
 Content-Length: 0
 
I would first advice to enable Reputation Defense in the Security settings and this should go down by 90%
 
Hi thanks for help. I do not see such option in security settings. Do you mean Security Barrier (Red) ?
what is good amount of requests to blacklist ip?

These requests pretend coming from my internal network.
 
Ok thanks but this option is enabled. How i wrote these requests pretend to coming from white listed ip of my router.
 
Since V16 i was thinking hack attempt would be low, i reopen 5060 and in one day 15 IP blacklisted even withoption enabled, i've no better feeling than previously in V15.5.
So now 5060 is restricted once again to my sip provider only and no more problems, just firewall checker red because of that restricted setting.
 
You 100% sure this isnt a legit EXT using an Aveya handset trying to connect via STUN/SBC?

you could always refresh credentials and push out to that ext.
 
Yes kieferschild 100% these are not legit extensions. These requests come from France and even from my home internet provider ip adreses. In office there are only 2 phones and 2 softphones. Nothing more. I saw requests coming even from my home ip address. But that is impossible. Someone realy likes to get in :)

You 100% sure this isnt a legit EXT using an Aveya handset trying to connect via STUN/SBC?

you could always refresh credentials and push out to that ext.
 
In your post, you show IP 212.83.174.223, it resolves to rev.poneytelecom.eu . Is that your provider? Does it come from other IPs as well? Do you have the blacklist time set to a very high number?
 
In your post, you show IP 212.83.174.223, it resolves to rev.poneytelecom.eu . Is that your provider? Does it come from other IPs as well? Do you have the blacklist time set to a very high number?
That ip is attacker ip. I replaced my ip with text myofficeip. I used default blacklist timigs now i set them to just few.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,918
Messages
589,737
Members
164,792
Latest member
LBS Care