Port Firewall rules

Status
Not open for further replies.

Hayward-i1

SOHO User
Joined
Oct 4, 2023
Messages
61
Reaction score
16
I have been a 3cx user since Version 9!

When I first installed 3cx, I got a LOT of hacking from outside my network so changed my firewall to all block all the 3cx ports that were NOT from my SIP trunk provider.

However, I am now wondering if this was/is necessary.

Therefore some advise please. To stop hacking can I just restrict connections to port 5060-5065 to my trunk/sip provider and leave the other UPD port completely open (9000-10500)?
 
This would depend on your requirements..

https://www.3cx.com/docs/manual/firewall-router-configuration/

Advises on what ports are used by what.

As long as you've not changed any of the security defaults provided by 3CX's anti-hacking and your user accounts are using secure passwords you should have no issues.
 
Thank you for the link. I was aware of the port configuration guide, but my questions relates specifically to the situation where I have locked access to my SIP/Trunk provider.

I also know I could let 3cx handle the blocking (rather than do it with the firewall) but at the time the attempts became so prolific that it consumed the total line capacity which in turn stopped everything else from working and I am not keen to repeat.

When I implemented the solution to block access to the 3cx ports at the firewall, the hacking stopped completely and has never returned.

However the configuration of the firewall itself is now very complex and if I do not need to block the UDP ports, I would rather remove this rule and limit access to just the 5060-5065 ports.
 
You shouldnt let 3CX be your first line of defence, and should always utilise the hardware firewall.

The fact your firewall configuration has become "complex" is a you issue. By default the firewall blocks all in, so what are you doing?

What do you want to achieve? sounds like you've already restricted to your SIP provider so whats the question here? Just restrict the ports to your SIP provider as mentioned in the guide linked above.
 
Wow, that's not the kink of response I was expecting.

My question, which I thought was clear, is can I just restrict the 5060-5065 ports to my SIP/Trunk provider to achieve the same level of security I currently enjoy.

If you do not know the answer, please don't bother responding.
 
Your initial question states:

...so changed my firewall to all block all the 3cx ports that were NOT from my SIP trunk provider.

Which means all traffic to/from your SIP provider you've opened.

All you're asking is if you can further restrict that down to the ports specified in the 3CX guide which i've referred you to 3 times now.

Restrict it. You wont receive the same level, but a higher level.

Note that anyone connected on STUN will stop working.
 
" firewall to all block all the 3cx ports that were NOT from my SIP trunk provider"

... if I do not need to block the UDP ports, I would rather remove this rule and limit access to just the 5060-5065 ports.

It's a simple enough question, and I am no novice to 3cx or firewalls. And it is strange that if you use the 3cx firewall checker blocking all these ports to your sip/trunk provider results in an error, lots of errors so I am guessing most people do not restrict these ports.

As I said, if you do not know the answer....
 
Yes of course you're going to get a failed firewall test if you restrict the ports down as you're blocking everything but the SIP provider. Most people tend to pass the firewall test and then restrict the firewall down so that the mgmt console is green. What more do you need answering?
 
Yes, if you want to stop massive tries on 5060 SIP port then obviously it's a good way to restrict to sip provider only .
 
@Hayward-i1 You can restrict ports 5060 and 5061 from the article. (5062-5065 are not listed...?)

The firewall checker is only a one-time test. If you ever have problems with audio etc. you can remove any port restrictions, run the firewall checker so it passes, and test to see if your problem still occurs. And then restrict the ports again afterwards.

We also restrict 5001/443 by country.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet