Security - PCI Compliance

Status
Not open for further replies.

prime5

Silver Partner
Joined
Apr 9, 2012
Messages
2
Reaction score
0
I'm on v15.5 right now. I need to upgrade to v16 but failed the recent PCI compliance scan. I want to get that fixed before jumping into a new issue. I don't have the Security - PCI compliance checked off on the phone system right now. We have Yealink T38G's. From what little I've found it looks like those won't work if I turn it on. The other forum post I was reading was a cloud install of 3CX. We are self-hosted internally.
Anyone know if there are other issues I may run into. Will the SIP trunk need to be adjusted if I enable the PCI Compliance security setting?
I scanned through the manual but I didn't see what all happens when it's enabled. It's a production server and I don't have a test server readily available or the same phone model to test.

Thank you for any input.

Andy
 
If you are serious about PCI compliance then the correct answer is to move 3CX and the phones out of your CDE with either physical or logical separation (VLAN).

Otherwise, the PCI compliance check box is pretty self-explanatory:

14230

Unless you are using TLS for your SIP trunk, it won't be affected.

Regarding the T38G phones they will work just fine as you have 3CX in-house and the phones are local and thus don't use the https port:
https://www.3cx.com/sip-phones/yealink-t32g-t38g-t42g-t46g/
14231

And as per that note if you did have those phones remotely they can still work but you would have to disable the certificate check.
 
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,817
Latest member
Innovative Advisory