- Joined
- Jun 18, 2020
- Messages
- 16
- Reaction score
- 0
I can't be the first person to do this... Couple of questions...
We are going live soon with our on-premise server. ( I am using a left-over server and it is more powerful than need-be for running 3CX.)
I have noticed for a while that random blacklisted IP addresses were appearing (because of hackers). I know that 3CX uses secure passwords and I even lowered the setting to blacklist after only 7 attempts. I know that there is a feature to share these blacklisted IP Addresses in a hope to stop the hackers -- but I opted for another approach.
We only have offices in 4 states. I looked up all of the IP blocks in those 4 states (plus verizon ip-blocks, charter cable IP-blocks, etc. etc.) These are the blocks of IP addresses that we may need (for folks wandering around with smartphones).
I created a list of network-blocks of public IP addresses that was basically everything else (that we probably do not need) -- in other words... Most of the world.
This massive BlackList of IP segments is about 380 entries. My blacklist entries vary from a /13 subnet to a /5 subnet. This does not block everything, but blocks a huge amount of the IPv4 internet. It uploaded into 3CX easily.
As far as I understand, if I whitelist an IP address (allow instead of deny), this not only over-rides the BlackList, but will never get "blocked" if a hacker is guessing passwords. I have only "whitelisted" our internal subnets and the public IP addresses of our remote offices.
I discovered that e-mail-sending did not really work right until I un-blacklisted the Google Cloud Range.
So far, this seems to be working really well (but we have not yet gone live yet.) Is there something I am not considering yet?
I am thinking that if I did have a random traveler on the smartphone app that is having difficulties, they can just read me their IP address (from IP chicken) and I can simply delete that block of IP addresses from the blacklist. This takes effect immediately.
Does anybody know if the blacklist only applies to ports 5090 and 5060 only? (Our phones do not do STUN -- so we really don't need 5060 open on the firewall).
I tried using an already registered smartphone APP from a "blacklisted" IP, and it actually could make calls! (the user listing. the "presence" and "chat" did NOT work). Does this mean that port 5001 is all that is needed for a smartphone to make a call? (assuming it has already been registered)
What would be a really cool security feature would be to have the ability to block all new phone registrations coming from Countries specified. I notices that most all of the hackers were coming from outside the US. (Interestingly, one hacker was coming from INSIDE the Redmond Microsoft IP block HUH???) For IPv4 it is not too terribly hard to get public IP blocks used in each country.
Am I the only one to do this? Any foreseeable problems? Any thoughts?
We are going live soon with our on-premise server. ( I am using a left-over server and it is more powerful than need-be for running 3CX.)
I have noticed for a while that random blacklisted IP addresses were appearing (because of hackers). I know that 3CX uses secure passwords and I even lowered the setting to blacklist after only 7 attempts. I know that there is a feature to share these blacklisted IP Addresses in a hope to stop the hackers -- but I opted for another approach.
We only have offices in 4 states. I looked up all of the IP blocks in those 4 states (plus verizon ip-blocks, charter cable IP-blocks, etc. etc.) These are the blocks of IP addresses that we may need (for folks wandering around with smartphones).
I created a list of network-blocks of public IP addresses that was basically everything else (that we probably do not need) -- in other words... Most of the world.
This massive BlackList of IP segments is about 380 entries. My blacklist entries vary from a /13 subnet to a /5 subnet. This does not block everything, but blocks a huge amount of the IPv4 internet. It uploaded into 3CX easily.
As far as I understand, if I whitelist an IP address (allow instead of deny), this not only over-rides the BlackList, but will never get "blocked" if a hacker is guessing passwords. I have only "whitelisted" our internal subnets and the public IP addresses of our remote offices.
I discovered that e-mail-sending did not really work right until I un-blacklisted the Google Cloud Range.
So far, this seems to be working really well (but we have not yet gone live yet.) Is there something I am not considering yet?
I am thinking that if I did have a random traveler on the smartphone app that is having difficulties, they can just read me their IP address (from IP chicken) and I can simply delete that block of IP addresses from the blacklist. This takes effect immediately.
Does anybody know if the blacklist only applies to ports 5090 and 5060 only? (Our phones do not do STUN -- so we really don't need 5060 open on the firewall).
I tried using an already registered smartphone APP from a "blacklisted" IP, and it actually could make calls! (the user listing. the "presence" and "chat" did NOT work). Does this mean that port 5001 is all that is needed for a smartphone to make a call? (assuming it has already been registered)
What would be a really cool security feature would be to have the ability to block all new phone registrations coming from Countries specified. I notices that most all of the hackers were coming from outside the US. (Interestingly, one hacker was coming from INSIDE the Redmond Microsoft IP block HUH???) For IPv4 it is not too terribly hard to get public IP blocks used in each country.
Am I the only one to do this? Any foreseeable problems? Any thoughts?