Suspicious activity (flood)

ITSP

Premier Customer
Joined
May 4, 2022
Messages
66
Reaction score
10
We recently got a lot of these from different IPs (mostly from China, Russia and Hong Kong):

The IP 185.7.214.105 on PBX blahblahbla has been blacklisted and will expire on: 2025/04/26 22:45:47.

Affected Module: Tunnel Manager

User agent:



Reason: Blocked due to suspicious activity (flood)



This IP Address 185.7.214.105 has made numerous attempts to authenticate with 3CX using invalid credentials. In response, 3CX has blacklisted this IP and denied any further requests.



No action is required on your behalf.

I know 3CX is doing its job and blacklisting the IPs but just wondering if there is anything else we can do to stop these. What is the Tunnel Manager used for anyway and what ports does it use (thinking of blocking those ports on the firewall)?
 
Ensure that you have the option below enabled and this ip will be added in the Global 3CX Blacklist:

attachment
 
If you don't have travelling users, you can safely block these IPs from your firewall as well. A lot of firewalls have geofencing, so you can block requests from countries you don't have any connection to.
 
  • Like
Reactions: ITSP and Evolute IT

Latest Posts

Forum statistics

Threads
111,963
Messages
589,998
Members
164,868
Latest member
swegner