- Joined
- Feb 2, 2022
- Messages
- 10
- Reaction score
- 3
Hello together,
my instance is running in the 3CX datacenter without any problems. It’s just one very annoying issue. Every day I get like 10-15 mails informing me that someone tried to connect to my instance with wrong username/password and the IP gets automatically blocked.
The effected module is always the SIP-Server. The IP-Addresses are spanning all over the world and most are identifying as a Polycom Phones (which I don't use at all internally). All my internal traffic is forwarded by a 3CX session controller to the system.
As far as I understand the Logs it is an external sip request to my public IP trying to find a weak username/password combination to get calling access to my PBX. I’m pretty sure they will never get a valid combination especially as I’m blocking WAN requests. But these mails are very annoying.
Aren't there any firewall rules in charge only allowing the known IPs of the given SIP-Providers to access the System? Or is it all open to everyone? Is there anything I can do to harden the system? Is this an issue that only I got or is this very common and I have to simply deal with it?
Happy to hear your responses
Best regards Timo
my instance is running in the 3CX datacenter without any problems. It’s just one very annoying issue. Every day I get like 10-15 mails informing me that someone tried to connect to my instance with wrong username/password and the IP gets automatically blocked.
The IP xxx.xxx.xxx.xxx on PBX <<PBX-name>> has been blacklisted and will expire on: 2022/02/12 09:00:05.
Affected Module: SIP Server
User agent: PolycomVVX-VVX_300-UA/4.1.6.4835
Reason: Too many failed authentications!
This IP Address xxx.xxx.xxx.xxx has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.
No action is required on your behalf.
The effected module is always the SIP-Server. The IP-Addresses are spanning all over the world and most are identifying as a Polycom Phones (which I don't use at all internally). All my internal traffic is forwarded by a 3CX session controller to the system.
As far as I understand the Logs it is an external sip request to my public IP trying to find a weak username/password combination to get calling access to my PBX. I’m pretty sure they will never get a valid combination especially as I’m blocking WAN requests. But these mails are very annoying.
Aren't there any firewall rules in charge only allowing the known IPs of the given SIP-Providers to access the System? Or is it all open to everyone? Is there anything I can do to harden the system? Is this an issue that only I got or is this very common and I have to simply deal with it?
Happy to hear your responses
Best regards Timo