Multiple failed authentication timeouts from various IPs.

Status
Not open for further replies.

JDesjardine

Customer
Joined
Jun 24, 2021
Messages
10
Reaction score
1
We are trying to find ways to harden our hosted 3cx. We have had weeks now of " The IP has been blacklisted Reason: too many failed attempts." We are wondering if there is a way to have our public IP cycled or for additional hardening measures to take to prevent this from happening.

Thanks,
 
If you are self hosting or running a non premise installation you can configure your firewall to allow only known IP addresses.
If you are using Hosted by 3CX then that is not an option. Just make sure you are not using weak passwords and you follow security guidelines.
We have a series of blog posts online to help you harden your security and avoid common pitfalls.
 
  • Like
Reactions: IrinaP_3CX
For some organisations setting up a firewall rules is an option. However if you are in a large organisation with a lot of sites spread over multiple (more then 10) countries and then add in the era of home-working, this is just not feasable.
What would be a big help for us to manage this, is to see what extensions cause IP's to be black listed.
In our experience there a lot of end users that cause this because of using wrong credentials or not scanning the new QR-code with the smartphone .
 
For some organisations setting up a firewall rules is an option. However if you are in a large organisation with a lot of sites spread over multiple (more then 10) countries and then add in the era of home-working, this is just not feasable.
What would be a big help for us to manage this, is to see what extensions cause IP's to be black listed.
In our experience there a lot of end users that cause this because of using wrong credentials or not scanning the new QR-code with the smartphone .
If you have these requirements then self hosted in the way to go. You can see the blacklist, add or remove IPs and see the logs to see what caused it.
 
Hi Yiannis, thx for your reply.
Unless I'm mistaken, you can not see in the logs what account was used for the failed logon attempt.
Yes you can see in the log = "...Reason: 3CX Clients / Softphones blocked - 3CX API Component
3CX Clients / Softphones ID: 12290" . But this does not tell me what extensons was used.
Please correct me if I'm wrong.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet