Solved No Inbound Firewall rule to limit access to PBX?

Status
Not open for further replies.

Timo83

Trial User
Joined
Feb 2, 2022
Messages
10
Reaction score
3
Hello together,

my instance is running in the 3CX datacenter without any problems. It’s just one very annoying issue. Every day I get like 10-15 mails informing me that someone tried to connect to my instance with wrong username/password and the IP gets automatically blocked.

The IP xxx.xxx.xxx.xxx on PBX <<PBX-name>> has been blacklisted and will expire on: 2022/02/12 09:00:05.

Affected Module: SIP Server
User agent: PolycomVVX-VVX_300-UA/4.1.6.4835

Reason: Too many failed authentications!

This IP Address xxx.xxx.xxx.xxx has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.

No action is required on your behalf.

The effected module is always the SIP-Server. The IP-Addresses are spanning all over the world and most are identifying as a Polycom Phones (which I don't use at all internally). All my internal traffic is forwarded by a 3CX session controller to the system.

As far as I understand the Logs it is an external sip request to my public IP trying to find a weak username/password combination to get calling access to my PBX. I’m pretty sure they will never get a valid combination especially as I’m blocking WAN requests. But these mails are very annoying.

Aren't there any firewall rules in charge only allowing the known IPs of the given SIP-Providers to access the System? Or is it all open to everyone? Is there anything I can do to harden the system? Is this an issue that only I got or is this very common and I have to simply deal with it?

Happy to hear your responses

Best regards Timo
 
  • Like
Reactions: AndreasY_3CX
Hi Timo,

As your 3CX installation is Hosted by 3CX, to Firewall that sits between it and the internet does indeed allow incoming traffic from all IPs on all the necessary ports 3CX requires to operate.

We cannot change the Firewall Rules for your specific case only, however note that if you follow the 3CX security guidelines as we talk about them here, your 3CX should be just fine and safe.
If you keep seeing that same IPs though appearing again and again, what you could consider doing is increasing the blacklist time interval so that the same IP's stay blocked for longer.
 
Hi Nick,

thanks for the fast reply. I can totally understand that the rules cannot be changed just for me. Mainly I just want to know if there are some restrictions on port 5060 present or not. This question is clearly answerd - thanks.

Please allow me two more thougths.
1. All traffic from IP-Phone or Mobile App should go over Port 5090 - so these port definitly needs to be open for all IPs. But what about the Port 5060 - here the connection is initiated from the PBX. No Phone should contact the PBX on this Port by there own. I don't know how it is called but its quite common for a firewall to only allow incoming traffic to a port after the door has been opend from inside. Would't this behaviour make it in total more save?

2. As I have decided to block all incoming WAN requests there is no need to inform me about that someone is trying to get access here. At the moment I have two possibilities: Block all unknow IPs from all services (wich is pretty much useless for remote workers) or disable all mail warnings (witch is also not what i want) - maybe this can be optimized in the future so that i can block all access to the sip server (besides my provider) but let the SBC and Weblogins untouched. Or to be able to disable notifications of SIP-Logon attemps when the WAN login is disabled.

Best regards

Timo
 
Hi Timo,

1. All traffic from IP-Phone or Mobile App should go over Port 5090 - so these port definitly needs to be open for all IPs. But what about the Port 5060 - here the connection is initiated from the PBX. No Phone should contact the PBX on this Port by there own. I don't know how it is called but its quite common for a firewall to only allow incoming traffic to a port after the door has been opend from inside. Would't this behaviour make it in total more save?
This is not quite the case, no. You are thinking about TCP connections like your browser when browsing to a website. This is not what happens here. SIP Trunks, which is the main reason we leave 5060 open usually use UDP transport, and any of the servers of the provider that you have signed up with may need to contact your 3CX IP to send you an incoming call.
Yes, usually providers will give you a list of IPs that you can whitelist, but:
a) This is not always the case
b) There are too many providers for us to add, plus these change over time so maintaining such a list would be problematic to say the least

On top of this, although we only recommend using IP Phones with SBC, but some users insist on manually configuring their IP Phones via STUN, which again requires 5060 to always be open from anywhere.


2. As I have decided to block all incoming WAN requests there is no need to inform me about that someone is trying to get access here. At the moment I have two possibilities: Block all unknow IPs from all services (wich is pretty much useless for remote workers) or disable all mail warnings (witch is also not what i want) - maybe this can be optimized in the future so that i can block all access to the sip server (besides my provider) but let the SBC and Weblogins untouched. Or to be able to disable notifications of SIP-Logon attemps when the WAN login is disabled.
While what you want is not currently an option (interesting idea though may I add...), if the issue here are the emails, what you could do is go to Settings --> Email --> Notifications, and here disable certain options about what email notifications should and shouldn't be sent to you.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet