Server network security best practices

Status
Not open for further replies.

GPO

Free User
Basic Certified
Joined
Mar 6, 2019
Messages
15
Reaction score
0
So that I can enable off network remote access, primarily via mobile phone apps, I am looking at the network design for a secure system. Having a 3CX server on my normal LAN with remote connections from random IP addresses does not feel comfortable and I will have a hard job getting that past my IT security manager. I cannot find a suggestion of this configuration but was wondering if the best way to approach this would be to have a SBC in my DMZ, acting as the endpoint for the SIP trunk and incoming remote devices with the main system still in my LAN, bridged to each other.

Would that proposed scenario work and I wonder what have others done when deciding where to physically locate their server to maintain security?
 
So that I can enable off network remote access, primarily via mobile phone apps, I am looking at the network design for a secure system. Having a 3CX server on my normal LAN with remote connections from random IP addresses does not feel comfortable and I will have a hard job getting that past my IT security manager. I cannot find a suggestion of this configuration but was wondering if the best way to approach this would be to have a SBC in my DMZ, acting as the endpoint for the SIP trunk and incoming remote devices with the main system still in my LAN, bridged to each other.

Would that proposed scenario work and I wonder what have others done when deciding where to physically locate their server to maintain security?

3CX is very secure itself. It has multiple security features because of the amount of attacks on VoIP systems.

What I would suggest is opening only the port 5060 from the IPs of your provider (same for RTP). Then only allow port 5090 which is the one used for mobile apps and SBCs (the tunnel port).

This way, you have a very secure system and it won't have a thousand failed authentication.
 
Mobile and 3CX clients do not use the SBC, it connects directly to the 3CX server using 3CX tunnel.
 
Thanks for the responses. It does seem that a standard 3CX install flies in the face of normal network best practice when it comes to device security and the internet, tunnels or otherwise, which is odd.
 
Thanks for the responses. It does seem that a standard 3CX install flies in the face of normal network best practice when it comes to device security and the internet, tunnels or otherwise, which is odd.

I'm really confused by this statement. How exactly do you think 3CX goes against network best practice?
 
  • Like
Reactions: Evolute IT
By allowing incoming connections from the internet on random IP's to a host located LAN side and not in a DMZ. I would not have an SMTP or FTP server for example LAN side and accepting connection from any external IP. So in the absence of a Session Border Controller that every other system uses can you tell me how exactly you think that 3CX follows networking best practices then please, I am willing to learn.
 
By allowing incoming connections from the internet on random IP's to a host located LAN side and not in a DMZ. I would not have an SMTP or FTP server for example LAN side and accepting connection from any external IP. So in the absence of a Session Border Controller that every other system uses can you tell me how exactly you think that 3CX follows networking best practices then please, I am willing to learn.

Euh, 3CX has an SBC by the way.
 
@GPO
What Frederick said:
  • Restrict 5060 UDP/TCP for only the IPs that need (usually those of your SIP Trunk provider)
  • Restrict 9000-10999 UDP for only the IPs of your SIP Trunk providers Media Gateways
  • Leave 5090 TCP/UDP open for Tunnel
  • Leave 5001 TCP open for presence for remote users
I don't see how you don't consider this safe:
  • 5001, you can restrict the Management Console access now in V16 to certain IPs, which will only allow presence to work from everywhere
  • 5090, its the tunnel port which is protected with a 13-digit (default, can be longer) alphanumeric password, so brute forcing is not an option. also, in the unlikely event that this IS compromised. then you also must know the SIP credentials to register which again by default has 8-digit random username AND password (can be longer). On top of all that, the Tunnel isn't a known protocol, so it would be extremely hard to reverse-engineer it. Additionally we do Penetration Testing against all services, including this one, and fuzzing and getting the password is not possible is it is hashed during the setup of the Tunnel.
I know there is the saying "nothing is unhackable", but I think it is in a pretty spot as far as security goes.
 
I suggest putting the 3CX server in your DMZ zone. You can also put a SBC in the LAN zone so that compatible phones show up in the 3CX console initially. When assigning them to an extension, switch them from using the SBC to a direct IP/LAN connection to the 3CX server.

You'll obviously need to open up the necessary ports from WAN to DMZ and DMZ to LAN, but now you have the same setup you would for any public facing server.

This is how we did it, just like any other public facing server.
 
Last edited:
  • Like
Reactions: GPO
I think the use cases are greater for a DMZ and less for a LAN. If you have an external SIP, remote offices, and remote users with the app, I don't know how you could put the server anywhere other than a dmv securely.

I would only put it in the LAN if you only have internal phones inside the network, and an internally terminated SIP. But then you're not using a lot of the 3CX features.

Are you suggesting that 3CX wants the server in the LAN and not the DMZ? I have not seen that documentation anywhere.
 
By allowing incoming connections from the internet on random IP's to a host located LAN side and not in a DMZ. I would not have an SMTP or FTP server for example LAN side and accepting connection from any external IP. So in the absence of a Session Border Controller that every other system uses can you tell me how exactly you think that 3CX follows networking best practices then please, I am willing to learn.

Umm 3CX doesn't place itself on your network, you do. Just like the SMTP or FTP server you can place it anywhere. So if you put it on your internal LAN that is you not following best practices, not 3CX.
 
  • Haha
Reactions: GPO
Insightful...
 
Thank you for all of your comments, we're going to have a conference call with 3CX and our new partner on ways to increase security and satisfy our requirements.
 
@GPO - do us all a favor and post back what gets determined. In the grand world of enterprise security, I'm curious how you ultimately decide to lock it down.
 
Not a problem at all, very little out there on what others have done so happy to contribute what we decide.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,920
Messages
589,743
Members
164,794
Latest member
avmullins