Unidentified Incoming Call Warning Event ID: 30051

cpe90

Customer
Joined
Mar 7, 2023
Messages
78
Reaction score
19
Hi guys,

Over the past 30 days, I've received over 300+ warning messages about Unidentified Incoming Calls.
I have reached out to SIPTRUNK.com support for clarification about this error, and they indicated that this could be an internal issue.
However, I did not recognize the IP as one of our internal IP addresses. I also did not find any information in our firewall traffic log about this IP address hitting our firewall.

The IP was 172.86.73.118. 216.126.227.248, 45.59.114.67, to name a few.
(x.x.x.x) is our public IP address of our 3CX server that I decided to hide.

Is this warning notification something that I can ignore, or has our 3CX been compromised in some way?


Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:0011447400700255@(x.x.x.x) SIP/2.0. Via: SIP/2.0/UDP 172.86.73.118:57355;rport=57355;branch=z9hG4bK-4d6393303929483781d097dacde5b0e9. Max-Forwards: 70. Contact: <sip:[email protected]:57355>. To: <sip:0011447400700255@(x.x.x.x)>. From: <sip:test@(x.x.x.x)>;tag=e83ce5f455044ebf971732a2cc36e82c. Call-ID: [email protected]. CSeq: 1 INVITE. Content-Type: application/sdp. User-Agent: Cisco-SIPGateway/IOS-12.0. Content-Length: 454. v=0. o=Z 0 0 IN IP4 172.86.73.118. s=SIP Call. c=IN IP4 172.86.73.118. t=0 0. m=audio 57355 RTP/AVP 0 8 18 3 110 97 9 98 99 111 101. a=rtpmap:0 PCMU/8000. a=rtpmap:8 PCMA/8000. a=rtpmap:18 G729/8000. a=fmtp:18 annexb=no. a=rtpmap:3 GSM/8000. a=rtpmap:110 speex/8000. a=rtpmap:97 iLBC/8000. a=fmtp:97 mode=30. a=rtpmap:110 opus/48000. a=rtpmap:9 G722/16000. a=rtpmap:98 speex/16000. a=rtpmap:99 speex/32000. a=rtpmap:101 telephone-event/8000. a=sendrecv

Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:000447400700255@(x.x.x.x) SIP/2.0. Via: SIP/2.0/UDP 172.86.73.118:57395;rport=57395;branch=z9hG4bK-75044a7918974c0aa714bb3e7f4970eb. Max-Forwards: 70. Contact: <sip:[email protected]:57395>. To: <sip:000447400700255@(x.x.x.x)>. From: <sip:784555922154@(x.x.x.x)>;tag=e376f09739fa4793b4ad4d35fb579af5. Call-ID: [email protected]. CSeq: 1 INVITE. Content-Type: application/sdp. User-Agent: Cisco-SIPGateway/IOS-12.0. Content-Length: 454. v=0. o=Z 0 0 IN IP4 172.86.73.118. s=SIP Call. c=IN IP4 172.86.73.118. t=0 0. m=audio 57395 RTP/AVP 0 8 18 3 110 97 9 98 99 111 101. a=rtpmap:0 PCMU/8000. a=rtpmap:8 PCMA/8000. a=rtpmap:18 G729/8000. a=fmtp:18 annexb=no. a=rtpmap:3 GSM/8000. a=rtpmap:110 speex/8000. a=rtpmap:97 iLBC/8000. a=fmtp:97 mode=30. a=rtpmap:110 opus/48000. a=rtpmap:9 G722/16000. a=rtpmap:98 speex/16000. a=rtpmap:99 speex/32000. a=rtpmap:101 telephone-event/8000. a=sendrecv

Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:00118163016305@(x.x.x.x) SIP/2.0. Via: SIP/2.0/UDP 216.126.227.248:54157;rport=54157;branch=z9hG4bK-264586745e0f42359251a7ff82633001. Max-Forwards: 70. Contact: <sip:[email protected]:54157>. To: <sip:00118163016305@(x.x.x.x)>. From: <sip:96320000129@(x.x.x.x)>;tag=edb102817dda4ba381d12f627c10dab4. Call-ID: [email protected]. CSeq: 1 INVITE. Content-Type: application/sdp. User-Agent: Cisco-SIPGateway/IOS-12.0. Content-Length: 458. v=0. o=Z 0 0 IN IP4 216.126.227.248. s=SIP Call. c=IN IP4 216.126.227.248. t=0 0. m=audio 54157 RTP/AVP 0 8 18 3 110 97 9 98 99 111 101. a=rtpmap:0 PCMU/8000. a=rtpmap:8 PCMA/8000. a=rtpmap:18 G729/8000. a=fmtp:18 annexb=no. a=rtpmap:3 GSM/8000. a=rtpmap:110 speex/8000. a=rtpmap:97 iLBC/8000. a=fmtp:97 mode=30. a=rtpmap:110 opus/48000. a=rtpmap:9 G722/16000. a=rtpmap:98 speex/16000. a=rtpmap:99 speex/32000. a=rtpmap:101 telephone-event/8000. a=sendrecv

Unidentified Incoming Call. Review INVITE and adjust source identification:. INVITE sip:00118163016305@(x.x.x.x) SIP/2.0. Via: SIP/2.0/UDP 45.59.114.67:50301;rport=50301;branch=z9hG4bK-4ffa940f41c1433b96ecf07ff197e90e. Max-Forwards: 70. Contact: <sip:[email protected]:50301>. To: <sip:00118163016305@(x.x.x.x)>. From: <sip:1001@(x.x.x.x)>;tag=55efccf77cd2406f912847fa4d9d5858. Call-ID: [email protected]. CSeq: 1 INVITE. Content-Type: application/sdp. User-Agent: Cisco-SIPGateway/IOS-12.0. Content-Length: 452. v=0. o=Z 0 0 IN IP4 45.59.114.67. s=SIP Call. c=IN IP4 45.59.114.67. t=0 0. m=audio 50301 RTP/AVP 0 8 18 3 110 97 9 98 99 111 101. a=rtpmap:0 PCMU/8000. a=rtpmap:8 PCMA/8000. a=rtpmap:18 G729/8000. a=fmtp:18 annexb=no. a=rtpmap:3 GSM/8000. a=rtpmap:110 speex/8000. a=rtpmap:97 iLBC/8000. a=fmtp:97 mode=30. a=rtpmap:110 opus/48000. a=rtpmap:9 G722/16000. a=rtpmap:98 speex/16000. a=rtpmap:99 speex/32000. a=rtpmap:101 telephone-event/8000. a=sendrecv
 
I am also seeing this on 3 phones systems and one does not have any sip providers as they have analog lines.
 
Hello,

Generally this is normal to see in the logs, and the system can handle them, including blacklisting repeat offenders.

In Admin->Advanced-->Anti-Hacking you can tune the blocking of such connection attempts, and also Opt-In to the 3CX Global Blacklist which helps minimize the impact from such fake call connections. This type of connection is similar to e-mail spam, just random IPs trying to connect and place calls directly to the PBX.

This document might be a good starting point for learning more: https://www.3cx.com/docs/allow-deny-ip-addresses/
 
  • Like
Reactions: YiannisH_3CX
To get rid of this restrict your sip port to the provider network. Keep in mind the firewall check will fail than.
 
  • Like
Reactions: KyriacosS_3CX
To get rid of this restrict your sip port to the provider network. Keep in mind the firewall check will fail than.
"AND any other IPs from which you might expect legitimate SIP traffic", needs to be said, 3CX installs are all unique ❄️
 
  • Like
Reactions: bitn2
To get rid of this restrict your sip port to the provider network. Keep in mind the firewall check will fail than.
Thanks. You already know it.
The firewall check will fail, and other issues may also appear.
Been there, done that. Lol.
I'm still hoping there's only a set of IP addresses that 3CX uses for the firewall check.
Maybe on version 30. :)
 
Thanks. You already know it.
The firewall check will fail, and other issues may also appear.
Been there, done that. Lol.
I'm still hoping there's only a set of IP addresses that 3CX uses for the firewall check.
Maybe on version 30. :)
There isnt any problem with that. Just do the firewall check and after that restrict your sip port. There are no other issues.
 
Hello,

Generally this is normal to see in the logs, and the system can handle them, including blacklisting repeat offenders.

In Admin->Advanced-->Anti-Hacking you can tune the blocking of such connection attempts, and also Opt-In to the 3CX Global Blacklist which helps minimize the impact from such fake call connections. This type of connection is similar to e-mail spam, just random IPs trying to connect and place calls directly to the PBX.

This document might be a good starting point for learning more: https://www.3cx.com/docs/allow-deny-ip-addresses/
Thank you for the info.

We have already used the anti-hacking settings and opted in to the global blacklist.
I wish there were another option to block connections from other countries besides our own automatically.
On my firewall, I'm already seeing IPs from 11 different countries trying to exploit SIP INVITE Method Request Flood Attempt or Realtek Jungle SDK Remote Code Execution Vulnerability.
 
There isnt any problem with that. Just do the firewall check and after that restrict your sip port. There are no other issues.

Okay, I will close it down to only our SIP provider again then.
Thank you for the advice.
 
  • Like
Reactions: bitn2

Latest Posts

Members Online Now

Forum statistics

Threads
111,831
Messages
589,276
Members
164,660
Latest member
RJenkinsROCK