PCI Compliance

Status
Not open for further replies.

darnell

Bronze Partner
Basic Certified
Joined
Sep 12, 2016
Messages
17
Reaction score
2
Hi

One of our clients has a card machine on their network and need to run PCI Compliance scans, it keeps failing on port 5060:

SIP UDP Transport Supported port 5060 /udp

I have port 5060 forwarded on the router using udp / tcp.

I have ticked:

Enable PCI compliance SSL/SecureSIP Transport and Ciphers (This will leave only TLSv1.2 enabled and may prevent old legacy phones and old 3CX Apps to connect remotely to your system)

In the 3CX Security settings.

Can I change the port forwarding to TCP instead of UDP / TCP on the router? Or will this cause issues?
 
Hi @darnell

The best thing to do is get your Sip providers external IP and lock 5060 to that.

Regards
 
To answer your question:
The question depends on what you have in the WAN to which 3CX needs to connect (VoIP Providers for example) and who need to connect to 3CX from the WAN (such as an IP phone).
The common transmission used by terminals is UDP.

To extend on your question:
Disabling UDP would probably not be the solutions. You may need to switch fully to TLS and could block 5060 (TCP and UDP) all together (plz don't before analysing all your needs and endpoints). TCP brings no meaningful security over UDP alone... additional TLS without the use of sRTP for the audio stream itself would be not a full coverage. 3CX supports both TLS for SIP and sRTP for audio transmission.

About PCI:
I am not a PCI expert to elaborate if UDP transmission for VoIP on the SIP port is allowed or not. I know that PCI likes encryption wherever it is possible (Requirement 4: Encrypt transmission of cardholder data across open, public networks ). If you (your customer) does not transmit over public networks in a phone call credit card information, then you may not need to follow PCI on the service. I would advise seeking legal counselling if your customer is in the need to operate under PCI and does transmit card details over the phone.
 
  • Like
Reactions: Evolute IT
The answer to every PCI compliance question on here is segment. Get everything out of your CDE that doesn't need to be in there.
 
I am not a PCI expert

Me neither, however it might be useful to know that there are 3rd party applications out there to assist with PCI compliance (recording of credit card details at least):
https://www.3cx.com/community/threads/what-are-you-using-for-pci-compliance.53938/

What you need to know is that during the call recording it should occur that the recording automatically stops during the call recording process (without any manual intervention from the agent).

This particular App works on pop-ups and browser information reading to achieve this and fills the card detail part of the recording with undetectable white noise.

It will also cover another important stipulation and that is that the recording file must at the end of the recording appear as one singular file.

Company who produces this: http://www.insperix.com/ (we install these fairly regularly) but it does come with an added cost.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,937
Messages
589,831
Members
164,818
Latest member
Guriqbal Singh