- Joined
- Feb 21, 2019
- Messages
- 168
- Reaction score
- 41
Good Day,
We have a branch office who is experiencing a concentrated and prolonged hack attempt by someone using spoofed IP's on port 5060. They are attempting to register a phone with thousands of attempts that has lasted two weeks now. Some notes:
- Remote users use softphones through the port 5090 tunnel.
- "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)" is turned on for all extensions.
- Each extension has a randomly generated user name and password that are quite complex.
- The hacker was recycling IP's when they became unblocked, so I extended the time they were blocked on the server dramatically.
Basically, it's impossible for them to log on, but the attempts are clogging my server with blocked IP's (currently 420+) and while remote, it is possible they can use an IP of one of our remote workers and block them.
My question is, if we are using port 5090 for the softphone tunnel, can I turn off port 5060 on the firewall and stop these attempts at the firewall so they never make it to the server? The SIP has an independent internal connection so no issues there.
Thanks.
We have a branch office who is experiencing a concentrated and prolonged hack attempt by someone using spoofed IP's on port 5060. They are attempting to register a phone with thousands of attempts that has lasted two weeks now. Some notes:
- Remote users use softphones through the port 5090 tunnel.
- "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)" is turned on for all extensions.
- Each extension has a randomly generated user name and password that are quite complex.
- The hacker was recycling IP's when they became unblocked, so I extended the time they were blocked on the server dramatically.
Basically, it's impossible for them to log on, but the attempts are clogging my server with blocked IP's (currently 420+) and while remote, it is possible they can use an IP of one of our remote workers and block them.
My question is, if we are using port 5090 for the softphone tunnel, can I turn off port 5060 on the firewall and stop these attempts at the firewall so they never make it to the server? The SIP has an independent internal connection so no issues there.
Thanks.