- Joined
- Feb 25, 2022
- Messages
- 7
- Reaction score
- 1
Approximately 1 year ago, I posted this on this forum...
I have a plain vanilla on-prem 3CX PBX. My SIP trunk provider gave me an ESG device. One port is assigned an IP address that's on my local LAN, for my PBX to connect to, and another port connects to the SIP trunk provider.
The other day I suddenly have a number of people in my office complaining that they can't make or receive calls with the outside world. After some quick troubleshooting, I discover that the IP address for the SIP trunk ESG device has been blacklisted. I removed the IP from the blacklist, and inbound and outbound calling was immediately restored.
I reviewed the activity log, and discovered that there were numerous attempts to register a non-existent extension on my system. After some number of failed attempts, the phone system must automatically blacklist the IP where these rogue registration attempts are coming from. I noted the originating SIP telephone number, did some Internet searching, and found that the number is associated with nuisance telemarketing and robocalling. This suddenly started to make sense to me. The bad people that are doing the robocalls somehow get an extension on my phone system, and then start making a huge, huge number of calls, that look like they’re coming from my company. We eventually get a reputation for being an unwanted telemarketer/robocaller, and PSTN service providers start blocking our outbound calls. We’re left with trying to restore our reputation, and getting our number unblocked, while the bad people simply delete their extension from our system, and move on to victimize some other unsuspecting company to make their robocalls.
My question is, how do I prevent these extension registration attempts that originate from the SIP trunk provider's IP address? I only have phones inside the building, and don't need to support any external extensions, so I would think that there would be an easy way for me to do this, but I can't really find anything in the documentation, or this forum, that definitively answers this question.
I'm hoping there's a 3CX expert out here that can point me in the right direction. Thanks.
My SIP provider insisted that this was not their problem and abruptly closed my support ticket. I didn't find a solution to this problem, but there were no more attacks, so life went on as usual... until today. The bad people are back again with their rogue extension registration attempts, and the IP address to my SIP provider was blacklisted again. No calls could come in or go out until I removed the blacklisted IP.
I opened another support ticket with my SIP provider, hoping for a different outcome, being a year later, but alas, the response was exactly the same. It's not their problem.
With the provides ESG device, everything from the outside world is NAT'ed, so all traffic looks like it's coming from the internal LAN IP of the ESG device. I have no way to differentiate good traffic from bad traffic.
Is there a way to configure the PBX NOT to accept extension registrations from a specific internal IP address? If I could do that, there would be no more rogue extension registrations allowed from that ESG device, that IP address won't ever be blacklisted, and then my company won't lose inbound and outbound calling capability.
Is there a way to differentiate an inbound telephone call from an extension registration? Or do they both use the same port 5060 to establish a connection?
Sorry, I am not a SIP expert, but I'm hoping there are people on this forum that are. Thanks.
I have a plain vanilla on-prem 3CX PBX. My SIP trunk provider gave me an ESG device. One port is assigned an IP address that's on my local LAN, for my PBX to connect to, and another port connects to the SIP trunk provider.
The other day I suddenly have a number of people in my office complaining that they can't make or receive calls with the outside world. After some quick troubleshooting, I discover that the IP address for the SIP trunk ESG device has been blacklisted. I removed the IP from the blacklist, and inbound and outbound calling was immediately restored.
I reviewed the activity log, and discovered that there were numerous attempts to register a non-existent extension on my system. After some number of failed attempts, the phone system must automatically blacklist the IP where these rogue registration attempts are coming from. I noted the originating SIP telephone number, did some Internet searching, and found that the number is associated with nuisance telemarketing and robocalling. This suddenly started to make sense to me. The bad people that are doing the robocalls somehow get an extension on my phone system, and then start making a huge, huge number of calls, that look like they’re coming from my company. We eventually get a reputation for being an unwanted telemarketer/robocaller, and PSTN service providers start blocking our outbound calls. We’re left with trying to restore our reputation, and getting our number unblocked, while the bad people simply delete their extension from our system, and move on to victimize some other unsuspecting company to make their robocalls.
My question is, how do I prevent these extension registration attempts that originate from the SIP trunk provider's IP address? I only have phones inside the building, and don't need to support any external extensions, so I would think that there would be an easy way for me to do this, but I can't really find anything in the documentation, or this forum, that definitively answers this question.
I'm hoping there's a 3CX expert out here that can point me in the right direction. Thanks.
My SIP provider insisted that this was not their problem and abruptly closed my support ticket. I didn't find a solution to this problem, but there were no more attacks, so life went on as usual... until today. The bad people are back again with their rogue extension registration attempts, and the IP address to my SIP provider was blacklisted again. No calls could come in or go out until I removed the blacklisted IP.
I opened another support ticket with my SIP provider, hoping for a different outcome, being a year later, but alas, the response was exactly the same. It's not their problem.
With the provides ESG device, everything from the outside world is NAT'ed, so all traffic looks like it's coming from the internal LAN IP of the ESG device. I have no way to differentiate good traffic from bad traffic.
Is there a way to configure the PBX NOT to accept extension registrations from a specific internal IP address? If I could do that, there would be no more rogue extension registrations allowed from that ESG device, that IP address won't ever be blacklisted, and then my company won't lose inbound and outbound calling capability.
Is there a way to differentiate an inbound telephone call from an extension registration? Or do they both use the same port 5060 to establish a connection?
Sorry, I am not a SIP expert, but I'm hoping there are people on this forum that are. Thanks.