Massive IP Blacklist

Status
Not open for further replies.

edwindrood

Bronze Partner
Basic Certified
Joined
Jun 18, 2020
Messages
16
Reaction score
0
I can't be the first person to do this... Couple of questions...

We are going live soon with our on-premise server. ( I am using a left-over server and it is more powerful than need-be for running 3CX.)

I have noticed for a while that random blacklisted IP addresses were appearing (because of hackers). I know that 3CX uses secure passwords and I even lowered the setting to blacklist after only 7 attempts. I know that there is a feature to share these blacklisted IP Addresses in a hope to stop the hackers -- but I opted for another approach.

We only have offices in 4 states. I looked up all of the IP blocks in those 4 states (plus verizon ip-blocks, charter cable IP-blocks, etc. etc.) These are the blocks of IP addresses that we may need (for folks wandering around with smartphones).

I created a list of network-blocks of public IP addresses that was basically everything else (that we probably do not need) -- in other words... Most of the world.

This massive BlackList of IP segments is about 380 entries. My blacklist entries vary from a /13 subnet to a /5 subnet. This does not block everything, but blocks a huge amount of the IPv4 internet. It uploaded into 3CX easily.

As far as I understand, if I whitelist an IP address (allow instead of deny), this not only over-rides the BlackList, but will never get "blocked" if a hacker is guessing passwords. I have only "whitelisted" our internal subnets and the public IP addresses of our remote offices.

I discovered that e-mail-sending did not really work right until I un-blacklisted the Google Cloud Range.

So far, this seems to be working really well (but we have not yet gone live yet.) Is there something I am not considering yet?

I am thinking that if I did have a random traveler on the smartphone app that is having difficulties, they can just read me their IP address (from IP chicken) and I can simply delete that block of IP addresses from the blacklist. This takes effect immediately.

Does anybody know if the blacklist only applies to ports 5090 and 5060 only? (Our phones do not do STUN -- so we really don't need 5060 open on the firewall).

I tried using an already registered smartphone APP from a "blacklisted" IP, and it actually could make calls! (the user listing. the "presence" and "chat" did NOT work). Does this mean that port 5001 is all that is needed for a smartphone to make a call? (assuming it has already been registered)

What would be a really cool security feature would be to have the ability to block all new phone registrations coming from Countries specified. I notices that most all of the hackers were coming from outside the US. (Interestingly, one hacker was coming from INSIDE the Redmond Microsoft IP block HUH???) For IPv4 it is not too terribly hard to get public IP blocks used in each country.

Am I the only one to do this? Any foreseeable problems? Any thoughts?
 
You can just block IPs from connecting to the ports at your router or firewall. We allow US IPs, except we allow the 3CX webmeeting servers. We do it that way to keep the traffic off the 3CX server.

The mobile app should use 5090...https://www.3cx.com/docs/ports/.

You can also use Security Settings/Console Restrictions to allow only certain IPs to log in to the management part of the web server. (vs the web client for users)
 
You can just block IPs from connecting to the ports at your router or firewall. We allow US IPs, except we allow the 3CX webmeeting servers. We do it that way to keep the traffic off the 3CX server.

The mobile app should use 5090...https://www.3cx.com/docs/ports/.

You can also use Security Settings/Console Restrictions to allow only certain IPs to log in to the management part of the web server. (vs the web client for users)

Mobile app needs Tunnel 5090 (what you said) plus the Management port (Generally 443 or 5001).
 
Sounds like too much work but kudos for taking the time.
 
Sounds like too much work
:) I'm not sure I'd do it manually but we use pfSense and its pfBlocker package for us, our data center, and our clients, which can download the geo lists from MaxMind for free.

re: forseeable problems, the lists aren't necessarily perfect, and IPs move (https://azure.microsoft.com/en-us/b...e-of-non-us-ipv4-address-space-in-us-regions/) but at least it's a starting point, and doing it via a list service will presumably keep more up to date.

Edwin could also just Allow the one phone's IP right? https://www.3cx.com/docs/allow-deny-ip-addresses/ doesn't specifically say that I see but does Allow override Deny?
 
What I have is working great! Thanks for all the input. I would not recommend this for everybody but I want to just drop in one last note to finish this off.

Why I decided to create this IP block list in the 3CX console (instead of create a massive ACL on the fire-wall).
  • I have a powerful Dell server for 3CX (but less powerfull Firewall-- Ubiquiti ER 4)
  • The BlackList may be large on 3CX but is easy for my co-horts to delete a segment if there is a conflict
  • The Blacklist on 3CX gives me a lot of flexibility. (only blocks new phone registrations -- nothing else)
  • The Blacklist on 3CX does not interfere with normal inbound/outbound traffic.
About the port 5090/5001 thing
I have verified this scenario:
  • A smartphone APP is "Provisioned" (either from inside network or any other non-blacklisted network)
  • The same smartphone is "moved" to now be on a blacklisted outside IP address.
The Smartphone APP still can make and receive calls even though it is connected via blacklisted IP.
However, the 3CX "Presence" does not work. Also Internal Contacts do not work.

Whether this is a "bug" or by design, I am OK with this. I do not believe that this compromises any security. New phone registrations would not be successful from a black-listed IP address.

More Notes
  • My "Inside" network only contains phones and the 3CX phone server.
  • I only have an IPv4 connection to the outside world. (No IPv6 available to me now)
  • I am not blocking ANY out-bound ports in the firewall.
  • I am blocking pretty much ALL in-bound 5060 port traffic on the firewall (SIP trunk providers do not seem to need it but I have allowed it only form SIP provider IP address -- SysLog shows that there is no traffic "initiated" by the SIP provider)
  • In my list of 3CX blocked IP addresses, I think I am also blocking the 3cx webmeeting ip addresses. This does not seem to matter (the 3cx IP blacklist is only blocking new phone registrations -- not blocking webmeetings -- as far as I know.)
Summary
Out of 3,720,192,896 possible outside IP addresses I ended up blocking 79.2% of these addresses with my massive IP block-list containing only 395 entries. I have had no failed password attempts (from hackers) show up in my activity log since then (and I assume that most all hackers are in that 79.2%)

As far as I know, I can wander amongst 5 northwestern states, and whether I am on a private WiFi or am on Verizon or AT&T data network, my smartphone app will work just fine.

In the future, once one of our smartphone users report a problem, I just need them to tell me their IP address (from IPchicken.com) and I will delete the offending block.

If I get any more failed attempts (from hackers) I can do a whois lookup and see what ISP this is coming from and possibly block the entire ISP (if it is not needed) http: // itools.com/tool/arin-whois-domain-search
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,278
Members
164,662
Latest member
DejanMDS