Strange loss of registration/provisioning, resulting in IP blacklisting Yealink T40G

Status
Not open for further replies.

Nickj

Free User
Joined
Nov 15, 2021
Messages
2
Reaction score
0
This is now solved by re-provisioning but caused quite a few problems this morning. I wonder if anyone else has experienced the issue:

We have a very small system with 4 IP phones, all the phones run on PoE from the same switch, and 4 extensons, 2 of which are also allocated to the 3CX app, Its running the latest version of 3CX.
This morning I tried to log into the 3CX browser app/extension and was told that my IP was blacklisted, similarly trying to log into the management console gave the response there had been too many login attempts.
I logged in to the management page from my mobile over 4G and found from the log that our premises WAN IP address had been blacklisted because one of the IP phones had made multiple unsuccessful login attempts, I allowed the IP address and got access back. The IP phone had been working fine the previous day.
I reprovisioned the phone and the system is working again but I am at a loss why this happened?

Is there anything that might cause a phone to suddenly do this? is it something that I need to address in any way now its fixed?

Many thanks
3cx log pic 1.png
 
Unless you changed credentials, or re-generated passwords recently, then this would not be expected.

But keep an eye out just in case, and make sure your phones are not accessible from the internet.

If you are using STUN, switch to using a 3CX SBC and remove any port forwards at the remote office site.

This will keep your phones more secure.
 
Unless you changed credentials, or re-generated passwords recently, then this would not be expected.

But keep an eye out just in case, and make sure your phones are not accessible from the internet.

If you are using STUN, switch to using a 3CX SBC and remove any port forwards at the remote office site.

This will keep your phones more secure.
Thank you for your reply John, I will keep an eye on it. At present the system is running the 3CX PBX hosted on a local physical computer, all of our physical phones are on the same LAN as the PBX. Is setting up the SBC appropriate for this instance, my very quick read of the documentation on the SBC is that it is intended for cloud hosted applications.
If we install the SBC software, can it run on the same Debian box that is running the PBX?

Many thanks

Nick
 
If the phones are on the same network as 3CX a SBC is not necessary. The SBC tunnels/proxys the phones to the server.

The SBC is installed on another computer/VM at the location of the phones. On on one of the phones that support a built in SBC with 18u6.

The phones on the same LAN should not be connecting through the WAN IP address. See https://www.3cx.com/docs/creating-fqdn-split-dns/
 
  • Like
Reactions: JohnS_3CX
Thank you for your reply John, I will keep an eye on it. At present the system is running the 3CX PBX hosted on a local physical computer, all of our physical phones are on the same LAN as the PBX. Is setting up the SBC appropriate for this instance, my very quick read of the documentation on the SBC is that it is intended for cloud hosted applications.
If we install the SBC software, can it run on the same Debian box that is running the PBX?

Many thanks

Nick
When local no SBC is needed, so you should be fine without one in this case


found from the log that our premises WAN IP address had been blacklisted because one of the IP phones had made multiple unsuccessful login attempts

Here is a question for you: why are the phones being blocked via the WAN address if they are LAN phones?
Are they connecting to 3CX via WAN for some reason? In this case the blocking was justified and correct.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,285
Members
164,662
Latest member
DejanMDS