Port 5060 - Open or not?

Status
Not open for further replies.

systemstech

Bronze Partner
Basic Certified
Joined
Dec 1, 2009
Messages
51
Reaction score
1
Just looking for advice from the experts here on whether you generally recommend leaving port 5060 open or restricting access on your installs. I realize that use case would dictate whether they need to be open but looking for general advice on how others do it?
Thx
 
Depends, are you gonna use SIP Trunks or STUN phones?

If SIP trunks only: you can usually lock it down to your provider's IPs.

If STUN phones: leave it opened. 3CX has good defences.

If none of those: close it just to be safe. The apps and SBCs use the 5090 tunnel port.
 
That was my feeling as well, just rolled out a stun phone and had to open it up and was wondering what others feel about having 5060 wide open. Lots of bad actors out there trying to connect to 5060, but I suppose properly configured that should mean lots of ip's blacklisted.
 
That was my feeling as well, just rolled out a stun phone and had to open it up and was wondering what others feel about having 5060 wide open. Lots of bad actors out there trying to connect to 5060, but I suppose properly configured that should mean lots of ip's blacklisted.
Make sure the global blacklist is enabled and I would set the defence login attempts to something like 3 to 5. My 5060 is opened and I never got hacked.
 
  • Like
Reactions: ChrisC_3CX
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,982
Messages
590,117
Members
164,908
Latest member
FarizQasimov