Restrict IPs on SIP Port

Status
Not open for further replies.

Frank86

Bronze Partner
Joined
Jan 18, 2018
Messages
300
Reaction score
26
I assume it's good security practice to restrict in/outbound traffic on TCP/UDP SIP ports (5060 default if not changed during install) to the public IP addresses of the chosen SIP trunk providers. Should this be done only for the main site where the 3CX PBX is hosted? Or also for any remote site with a 3CX SBC?
 
You would restrict port 5060 on firewall protecting the 3cx server using firewall rules

With sbc , you have no inbound traffic just outbound (ports 5090 tcp and udp, port 443 or port 5001). You can restrict port 5090 inbound on the 3cx firewall, except note: below

Note : port 5090 (tcp and udp) , port 443 or 5001 is also used by 3cx ios / andriod and 3cx softphone - so if you have any of these clients you can not restrict these ports inbound to the 3cx server

Ports 443 and 5001 are also used by stun phones, for provisioning url
 
Last edited:
Sounds good. Thank you. Should port 5060 in/outbound be restricted to the LAN IP of the PBX? Or to any LAN IP?
 
Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,916
Messages
589,719
Members
164,785
Latest member
Texas Clay -