Notified of IP being blacklisted, but IP not showing up in blacklist

Status
Not open for further replies.

EbenisterieNorclair

Customer
Joined
Sep 7, 2021
Messages
13
Reaction score
0
I received several notifications of the same IP address being blacklisted, multiple times within minutes. Blacklist time interval is set to 86400 seconds. Bizzarely, the IP address does not show up under the IP Blacklist in the admin console... what can cause that behavior?

So I then tried to add the IP address to the blacklist manually, and I got the error "This IP address is already in the blacklist". Yet when I try and search on this IP address in the blacklist, it won't show up...

I experience this behavior with 2 IP addresses now.

Please advise.
 
Last edited:
Hi, I wonder if by any chance do you have a range of IPs set as deny that might include that IP address?
Yes I thought about that - I looked further into the blacklist, and no, it's not the case.

And if it were the case, then 3CX wouldn't be notifying me about blacklisting it multiple times within minutes, with my blacklist time interval set to 86400. The fact that 3CX does attempt to blacklist the IP address multiple times within minutes, seems to indicate that every attempt to blacklist it fails - similar to when I try to do it via the admin console.

Any idea what could cause this behavior?
 
what is the message and reason that is shown in the event log/email ?
 
  • Like
Reactions: N_G
what is the message and reason that is shown in the event log/email ?

Below is the email I receive - I just realized the timelapse for the blacklist is 15 minutes (900 seconds), rather than the 86400 that I have configured (!). This seems like a buggy behavior to me, but it explains why I don't find these entries in the blacklist when I go went and looked for them...

Not sure why these 2 last IP addresses got blackmailed for 15 minutes only, whereas I had several dozens of other IP addresses which were correctly blacklisted for 86400...

The IP xxx.xxx.xxx on PBX <company>.my3cx.ca has been blacklisted and will expire on: <time of email + 15 minutes>
Affected Module: Webclient / API
User agent:
Reason: Blocked for too many failed authentications
This IP Address xxx.xxx.xxx has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.
No action is required on your behalf.
 
(as a side note, it would be great if 3CX allowed for MUCH greater values in the "blacklist time interval" setting... I normally go in the blacklist and tweak the year so as to blacklist them for 100 years, e.g. 2023 > 2123 #featurerequest)
 
Hi @EbenisterieNorclair what you see here are failed LOGIN attempts to the Management Console/ Web Client. These are not SIP failed registration.

By default IPs blocked by failed login attempts are blocked for 15 minutes.

The blacklist interval 86400 will be used for the Anti-Hacking options like sip failed authentication, Failed Challenge Requests, etc...

You might enable the Management Console Restriction to your trusted static public ips.
 
Hi @Alejandro_3CX,
Understood re: the different type of blocked addresses and time intervals.

We do have Console Restrictions enabled, so as to allow access from specific IP Addresses - and the only IPs present in the list are those pre-populated by 3CX.

What really bothers me is the behavior in the IP Blacklist:
1. when I search for one of these IP addresses, it does not find it
2. when I try to add one of these IP addresses, it tells me it's already listed
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,963
Messages
589,998
Members
164,868
Latest member
swegner