Security of Remote (STUN) Deskphone

Status
Not open for further replies.

Alan9846

Silver Partner
Joined
Aug 24, 2019
Messages
96
Reaction score
19
Hi All,

We have a customer that has an on-premise install of 3CX (all up to date - Version 18 Update 5) running on Debian.

They have a number of remote users, some with desk-phones, and some on the 3CX App, working fine for years since we set them up on 3CX - they are on a Professional License (not that I think that has any impact, but just in case).

One user is working out of an office belonging to a supplier of our customer. They want to use a desk-phone, rather than the 3CX App on their smart-phone while they are in their office, so we have provisioned a YeaLink T46S using STUN (at our office), and took it out to setup for the user. However, it does not work in that there is no audio.

The issue appears to be due to a firewall at the office that is blocking ports, so we have asked for the desk-phone to be allocated a fixed (internal) IP, and for Ports 14000 to 14019 (RTP) and 14020 (SIP) to be forwarded to the desk-phone. The default is 5065 for SIP, but we figured to change that to 14020 so that there is a single continuous run of ports that we are asking to be forwarded. We also asked for both TCP and UDP to be forwarded on all of those ports. This is something we have done with other customers in the past, and never had any issues. For the avoidance of doubt, the desk-phone was provisioned like that in our office, and it worked fine here.

The IT people at our customer's supplier have come back and indicated their discomfort with opening those ports in their firewall due to security concerns. I am not unsympathetic in that respect. The only other option would seem to be to install an SBC at that location, and have the desk-phone talk to the SBC, which then goes out to the 3CX Server, but no incoming ports would need to be opened for it to work.

Setting up an SBC will incur some additional costs though, and we would prefer to avoid that for a single remote extension if at all possible.


My question is:

Does anyone have any references that we could provide to the IT people regarding the security of VOIP phones setup via STUN, and in particular, the security implications of the ports being forwarded for RTP and SIP to that desk-phone? I am guessing that their concern is that someone can get into the desk-phone, and from there, into the wider LAN.

Has anyone experienced any issues with such a setup, or have any thoughts on the security that you could share?



Thanks,

Alan.
 
You could always restrict incoming traffic from the 3cx server wan ip address on the firewall
 
  • Like
Reactions: CentrexJ
Advise here would be to use a 3cx SBC on site with the Ip phones to avoid any issues with ports and improve security: https://www.3cx.com/docs/3cx-tunnel-session-border-controller/

Hi Charles,

I appreciate that 3CX has to make this recommendation {wink} however, for one remote extension, an SBC seems like overkill, especially in the absence of any actual examples of a compromise, unless you can advise of any?

You could always restrict incoming traffic from the 3cx server wan ip address on the firewall

Hi Saqqara,

Yes - this would be a good idea. I will suggest it to them, and maybe it will assuage their concerns :-)


Thanks,

Alan.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet