tronic
Gold Partner
- Joined
- Apr 24, 2018
- Messages
- 394
- Reaction score
- 430
Is there a way to access the block list so we can do it at the firewall/router level?Hi,
Those are webclient bruteforce attempts, we added an event to give these more visibility as previously they would be logged only in the management console logs.
Although this isn't something new there are many scanners/bots out there looking for weak credentials, and it is advisable to stick to random/complex passwords everywhere as it is the case by default.
The Console restrictions option doesn't affect the webclient access but only the management console one.
Such offending IP addresses get eventually in the Global Blacklist once there have been multiple reports from different 3CX Systems, and after your blacklist resyncs (every 2 hours). I checked those and most are already listed on our end.