Solved Upgraded from v16 to v18, now 3cx nginx.exe trying to access sucuri.net?

Status
Not open for further replies.

dan_tx

Premier Customer
Joined
Nov 3, 2016
Messages
37
Reaction score
21
Just upgraded from v16 to v18 and we are now noticing outbound attempts to 192.124.249.41, port 80, by the 3cx built in NGINX program, nginx.exe . Currently being blocked, as we block by default inbound and outbound connections. IP lookup shows cloudproxy10041.sucuri.net for that ip.

Can we confirm this is normal and needs to be allowed? Can we also confirm the purpose? Judging from https://sucuri.net/ it appears used as a security option used by nginx, which is great, but I couldn't find any documentation on this new outbound connection that v18 is using.
 
Hi!

I am not aware of any such connection, let alone to port 80 which is non-encrypted.

Do you mind telling us how you know this is nginx making this connection?

If you are running on Linux maybe run the following to command to see the established connections:
Bash:
netstat -apn | grep 192.124.249.41
 
Hi!

I am not aware of any such connection, let alone to port 80 which is non-encrypted.

Do you mind telling us how you know this is nginx making this connection?

If you are running on Linux maybe run the following to command to see the established connections:
Bash:
netstat -apn | grep 192.124.249.41

Our third-party endpoint firewalll reports blocks and the program that attempted to make the connection is how I know it was nginx attempting the connection. It's a windows box.

I found what it was. After the upgrade we worked on getting SMS working, and part of that was adding the intermediate certificate to 3cx nginx.

Well per the log in the 3cx nginx folder I found this text.

2021/12/08 15:47:37 [error] 5528#5648: OCSP_basic_verify() failed (SSL: error:27069065:OCSP routines:OCSP_basic_verify:certificate verify error:Verify error:unable to get local issuer certificate) while requesting certificate status, responder: ocsp.godaddy.com, peer: 192.124.249.41:80, certificate: "C:\Program Files\3CX Phone System\Bin\nginx/conf/Instance1/**************


I'll need to figure that out, but now know the source of the connection and what caused it (adding/trying to add an intermediate certificate to the 3cx certificate file). The good news is we have SMS working with Twilio.
 
Ah, that's why I have never seen this.
Kind of makes sense.

Glad you got it figured out!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet