- Joined
- Oct 3, 2024
- Messages
- 34
- Reaction score
- 8
Hello!
We use 3CX on our own hardware - Linux version.
We use a VoIP gateway for stationary internal phones, mobile applications on smartphones, and a plugin for the 3CX talk site.
The following ports are open on the firewall for 3CX:
5060 (TCP UDP)
5090 (TCP UPD)
5001 (TCP)
9000-10999 (UDP)
Now there are many such events in the logs:
Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:[email protected] SIP/2.0. Via: SIP/2.0/UDP 107.189.19.185;branch=z9hG4bK-7b3c765268684fbe9a12b1dc88796a32. Contact: <sip:[email protected]>. To: <sip:[email protected]>. From: <sip:[email protected]>;tag=e1deb7ea31774c419327cd04ad3b22f5. Call-ID: [email protected]. CSeq: 1 INVITE. Content-Type: application/sdp. Content-Length: 123. v=0. o=- 0 0 IN IP4 107.189.19.185. s=Call. c=IN IP4 107.189.19.185. t=0 0. m=audio 12345 RTP/AVP 0. a=rtpmap:0 PCMU/8000
As I understand it, there is a brute force attempt on accounts and an attempt to connect.
How can such attempts be blocked?
We can block by IP on the firewall, but how can we obtain the list of IP addresses from which hacking attempts are made?
We use 3CX on our own hardware - Linux version.
We use a VoIP gateway for stationary internal phones, mobile applications on smartphones, and a plugin for the 3CX talk site.
The following ports are open on the firewall for 3CX:
5060 (TCP UDP)
5090 (TCP UPD)
5001 (TCP)
9000-10999 (UDP)
Now there are many such events in the logs:
| ID | 30051 |
Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:[email protected] SIP/2.0. Via: SIP/2.0/UDP 107.189.19.185;branch=z9hG4bK-7b3c765268684fbe9a12b1dc88796a32. Contact: <sip:[email protected]>. To: <sip:[email protected]>. From: <sip:[email protected]>;tag=e1deb7ea31774c419327cd04ad3b22f5. Call-ID: [email protected]. CSeq: 1 INVITE. Content-Type: application/sdp. Content-Length: 123. v=0. o=- 0 0 IN IP4 107.189.19.185. s=Call. c=IN IP4 107.189.19.185. t=0 0. m=audio 12345 RTP/AVP 0. a=rtpmap:0 PCMU/8000
As I understand it, there is a brute force attempt on accounts and an attempt to connect.
How can such attempts be blocked?
We can block by IP on the firewall, but how can we obtain the list of IP addresses from which hacking attempts are made?

