- Joined
- Sep 19, 2016
- Messages
- 34
- Reaction score
- 0
Having got our 3CX PBX running for a trial period, we have run into one problem with our external PCI Vulnerability scan.
Apparently, the HTTPS Webserver integrated with the 3CX PBX supports SSLv3 and TLS1.0, which are automatic fails now with the new PCI DSS 3.1 standard. I can request an exception...but I'd rather not deal with that paperwork if there is a simple fix
Is there anyway to disable these, and still keep registration working for remote Iphone/Android clients ? For now, I have simply blocked 5000/5001 at the firewall, but this then breaks presence on the smartphones.
My remote sites are thankfully all unaffected as they use IPSEC tunnels to communicate to the central location.
Thanks for any suggestions !
Steve
Apparently, the HTTPS Webserver integrated with the 3CX PBX supports SSLv3 and TLS1.0, which are automatic fails now with the new PCI DSS 3.1 standard. I can request an exception...but I'd rather not deal with that paperwork if there is a simple fix
Is there anyway to disable these, and still keep registration working for remote Iphone/Android clients ? For now, I have simply blocked 5000/5001 at the firewall, but this then breaks presence on the smartphones.
My remote sites are thankfully all unaffected as they use IPSEC tunnels to communicate to the central location.
Thanks for any suggestions !
Steve