Restricting SIP access to just the trunc

Status
Not open for further replies.

PvK

Customer
Joined
Apr 22, 2020
Messages
72
Reaction score
20
The port forwarding as explained in the documentation works fine. The firewall icon shows green on the dashboard. But I get these random people that are blocked by 3cx because they want to login in and use our pbx I assume. So I restricted access to the WAN SIP port on the firewall, to just the domain of the SIP Trunk. This works fine, but now the Firewall shows red, as the SIP "full cone test failed".

Is there another way to prevent unknown people to try and log-in?
 
Last edited:
  • 3CX Version, Standard Annual 16.0.612
  • Server OS, Windows 10
  • Is the 3CX Server Hosted and where? In house
  • Provisioning Method: Local
 
If you don't experience any other issues, with it set this way, then you could simply leave it as is and see what happens. 3CX is pretty good, on it's own, at thwarting hack attempts and does share a list of suspected IPs to be blacklisted. You can also do, things such as extending the blacklist timeout, to a much longer period.
 
Thanks,
I like my icons to be green :)
Looking in the online manual for the blacklist settings, I found this:

The 3CX anti-hacking Blacklist / Whitelist mechanism does not replace a firewall. It provides a defense mechanism to help separate traffic that is trusted, and traffic that is not trusted. If for example you want to block all traffic to your network and allow only your VoIP Provider IP address, you need to set this up on your firewall

I have now split the rules in pfSense, and left 5060 UTP open, the rest are closed except for the VOIP Provider IP address, then I don't get a warning.

Any tips why this would be?
 
I like my icons to be green :)
for Green just remove temporarily your firewall restriction on 5060, then run 3CX test , should be green as you like , then reactivate your restriction but don't run 3CX firewall checker.

Having 5060 restriction on SIP provider IP is not a problem even if red in firewall checker (this is just a test tool to help in case of problem.
 
for Green just remove temporarily your firewall restriction on 5060, then run 3CX test , should be green as you like , then reactivate your restriction but don't run 3CX firewall checker.

Having 5060 restriction on SIP provider IP is not a problem even if red in firewall checker (this is just a test tool to help in case of problem.
Merci bien!
 
  • Like
Reactions: AWS2P
Status
Not open for further replies.

Forum statistics

Threads
111,952
Messages
589,903
Members
164,845
Latest member
tdzski5