Repeated Windows warning event since upgrade to v18 SP4 Final

Status
Not open for further replies.

mcbsystems

Free User
Advanced Certified
Joined
Oct 9, 2019
Messages
44
Reaction score
19
Hi,

Running a small 4-line Standard instance on a Windows 10 21H2 x64 computer. Since upgrading to v18 SP4 last week, this error repeats in the Windows Application Event Log about 57 times a day:

Code:
Log Name:      Application
Source:        3CXManagementConsole
Date:          7/15/2022 1:59:27 AM
Event ID:      0
Task Category: None
Level:         Warning
Keywords:      Classic
User:          N/A
Description:
Category: ManagementConsoleJS.Controllers.Webclient.LoginController
EventId: 0
SpanId: 7375ab0e8089d749
TraceId: 234ab46974474d4c883e3be7305e2c2d
ParentId: 0000000000000000
ConnectionId: 0HMJ5V8R0SE53
RequestId: 0HMJ5V8R0SE53:00000002
RequestPath: /webclient/api/login
ActionId: a1891288-9275-4e75-be78-a8ef7efa7899
ActionName: ManagementConsoleJS.Controllers.Webclient.LoginController.Get (3CXManagementConsole)

User or password is invalid

I see it refers to the webclient login controller, but it happens when, to my knowledge, no one is logged in (e.g. 2am).

3CX is the only app on this computer. It uses basic Windows Defender anti-virus, which has not been a problem for the three years it has been in production.

I haven't heard any reports of issues yet. (I see another thread here that the 3CXPhoneSystem01 service was crashing under high load and that this message was also found, but this is a tiny system compared to that and the message is occurring under zero load.)

Any explanation of what this is? Should I just ignore these errors?
 
Last edited:
If its causing you no problems, then dont worry about it.
 
Do you have any pci compliance scanners on any of your internal computers?
 
No, no PCI scanners.

Yes, I'm inclined to agree that it can be ignored. However 3CX has usually been very well behaved re. not throwing spurious messages so I wanted to check.

Anyone else with a Windows install: do you see 3CXMangagementConsole warnings in the Application Event Log since the SP4 upgrade?

Hopefully someone from 3CX can confirm that this can be ignored, and put it in queue to be fixed in the future.
 
Mark,

I am seeing the same issue. Have you opened a ticket yet?
 
Chris - thanks for confirming. No, I haven't opened a ticket.
 
Any solution for this issue yet? My windows server keeps repeating this at high rate. All different ip addresses.

Marcel
 
Yes I'm still seeing it in SP5, looks like 100+ per day. After a little more review, I'd say it's probably routine hack attempts that you get whenever you have a port open to the Internet, so maybe it's good that 3CX is surfacing those.

I have port forwarding set up on the custom HTTPS port in the customer's router. After restricting that forwarding rule to only allow access from my IP address, the messages stopped. Of course, this only works if you can identify the specific IP address(es) that need HTTPS access from outside the firewall.
 
Which ip addresses should I allow? Which port?

Marcel
 
This is for INBOUND connections. The 3CX server is at my customer's office. In the customer's firewall, I allowed the IP address of my office to reach their 3CX server.

I believe the port is defined when you first set up 3CX, but you should see it in the URL when you connect to your dashboard. If you don't see a port in the URL, it would be the default for HTTPS, namely 443.

Note that this blocks any other user outside the firewall from accessing 3CX via the web interface.
 
This is for INBOUND connections. The 3CX server is at my customer's office. In the customer's firewall, I allowed the IP address of my office to reach their 3CX server.

I believe the port is defined when you first set up 3CX, but you should see it in the URL when you connect to your dashboard. If you don't see a port in the URL, it would be the default for HTTPS, namely 443.

Note that this blocks any other user outside the firewall from accessing 3CX via the web interface.
This also stops presence from working in the 3CX mobile apps, can affect bridges, may break SMS webhooks, etc
All this to say, be careful with closing that port.
 
  • Like
Reactions: mcbsystems
This also stops presence from working in the 3CX mobile apps, can affect bridges, may break SMS webhooks, etc
All this to say, be careful with closing that port.
The mobile apps use the HTTPS port? I thought they exclusively used the tunnel port.
 
The mobile apps use the HTTPS port? I thought they exclusively used the tunnel port.
Only for voice. Presence, Chat, etc are all HTTPS
 
Good to know, thanks.
 
We also see a lot of those warnings saying "User or password is invalid" in the Windows Event Log.

Is there a setting that will prevent 3CX Management Console from logging the warnings?

-- rpr.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet