Ultimate way to protect your cloud hosted 3cx?

Status
Not open for further replies.

ElementalWindX

Bronze Partner
Advanced Certified
Joined
Oct 24, 2018
Messages
367
Reaction score
40
Are there any processes we can put in place to ultimately protect our cloud based 3cx instances? IE using cloud flares dns proxy protection stuff? (although that's probably moot too because I'm sure most people just port scan public IP's to find my 3cx servers)

Unfortunately using a site to site VPN is out of the question for 99% of my clients who love to use the 3cx iphone/android app, and also blocking all except whitelisted IP's won't work since my clients don't utilize static IP's at their location.

So all my servers are constantly getting brute forced non-stop. I have the auto-ban settings on and all the security settings setup within 3cx itself.

What do you folks do?

It seems the only real option is putting a pfsense firewall in front of every instance and doing geo blocking is about the only decent step.
 
Or just accept that the internet is a scary place and trust 3CX to do it's job.
 
  • Like
Reactions: Evolute IT
change firewall setting for 5060 IPV4 and IPV6 if enabled , allow only SIP provider IP, like this no more attempt comes to 3CX, of course if you run firewall checker it will be red but you 'll know why.
 
Or just accept that the internet is a scary place and trust 3CX to do it's job.
it's in my blood to never trust software by itself. :)
 
putting a pfsense firewall in front of every instance and doing geo blocking is about the only decent step.
This is literally what we do (all are in our data center). I'd vaguely guess we get a blacklisted IP once a month or so (usually on all PBXs so they're just hitting all IPs).
 
Status
Not open for further replies.