Security - Best Practice

Status
Not open for further replies.

DrainBamaged

Forum User
Advanced Certified
Joined
Feb 21, 2019
Messages
168
Reaction score
41
Good Day,

What's the recommended Best Practice for eliminating (or at least reducing) the number of false registration attempts. One of our offices is being hammered with garbage registration attempts from random IP's. They are being blocked (we use strong passwords and lengthy random user names on all accounts), but it does not stop the attempts. We've restricted access from that country alone on the firewall, but they have responded by using VPN with exit points in the same country.

It's getting annoying and the emails are choking the account so spotting actual issues is much harder. All tips welcome.

View attachment 31511
 
Block port 5060 on the firewall except from your Trunk Provider IPs and anyplace you have remote IP phones using DirectSIP (STUN). Apps / SBC work over the tunnel port (5090) and do not need to be considered.
 
Excellent advice, thank you. Tested on a smaller field office and will be doing the HQ this weekend.

Banned IP's dropped to 0 during the test. No issues at all with softphones and cell apps on 5090.
 
Made the changes Saturday afternoon. Here are the results.

Saturday afternoon:

1661170978717.png

Monday morning:

1661171001995.png
IP's are blocked for a week so will be going down for a few more days. Not a single blocked email since I made the firewall changes. I'm calling this a win. Thank you @SweetAction
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet