Protection of 3cx from flooding

Oleksii

SOHO User
Joined
Oct 3, 2024
Messages
34
Reaction score
8
Hello!

We use 3CX on our own hardware - Linux version.
We use a VoIP gateway for stationary internal phones, mobile applications on smartphones, and a plugin for the 3CX talk site.

The following ports are open on the firewall for 3CX:
5060 (TCP UDP)
5090 (TCP UPD)
5001 (TCP)
9000-10999 (UDP)
Now there are many such events in the logs:
ID30051

Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:[email protected] SIP/2.0. Via: SIP/2.0/UDP 107.189.19.185;branch=z9hG4bK-7b3c765268684fbe9a12b1dc88796a32. Contact: <sip:[email protected]>. To: <sip:[email protected]>. From: <sip:[email protected]>;tag=e1deb7ea31774c419327cd04ad3b22f5. Call-ID: [email protected]. CSeq: 1 INVITE. Content-Type: application/sdp. Content-Length: 123. v=0. o=- 0 0 IN IP4 107.189.19.185. s=Call. c=IN IP4 107.189.19.185. t=0 0. m=audio 12345 RTP/AVP 0. a=rtpmap:0 PCMU/8000

As I understand it, there is a brute force attempt on accounts and an attempt to connect.
How can such attempts be blocked?
We can block by IP on the firewall, but how can we obtain the list of IP addresses from which hacking attempts are made?
 
Hello,

The Anti-Hacking options page allows you to set how sensitive your system will be to such attempts, and also to Enable the Automatic Global Blacklist that helps protect you and the whole community by sharing bad actor information. You should also use the IP Blacklist tab to make sure any IPs you know you want to talk too are always allowed, especially if you do strict anti-hacking configs.

1752482617010.png
 
  • Like
Reactions: Evolute IT
The anti-cheat parameters are set to default. The blacklist is currently empty. We also have country restrictions enabled - only Europe is included. Is there any option to export the blacklist or receive notifications for event 30051 in order to manually add wrongdoers to the block list?1752483032431.png
 
  • Like
Reactions: Evolute IT
You can restrict your sip port to your trunk provider. That could help to reduce stuff like this.
 
You can restrict your sip port to your trunk provider. That could help to reduce stuff like this.
Thank you! This is exactly what is needed in this situation!
 

Latest Posts

Forum statistics

Threads
111,961
Messages
589,954
Members
164,862
Latest member
ARTipsadmin