v15.5 Blacklist Problem

Status
Not open for further replies.

[email protected]

Premier Customer
Joined
Jun 17, 2015
Messages
84
Reaction score
21
I have an issue with our SIP provider where our blacklist feature blocks their IP every 30 days when the allow entry I've built expires. We've only been on this SIP provider for a couple of months so this is the 2nd time it's happened. Our SIP provider uses IP only with no authentication configured. I've contacted my SIP providers NOC and they're trying to figure out what our options are as they believe there is no authentication attempts occurring. They did a few test calls with packet captures so I'm hoping they find something wrong on their end.

I figured out how to extend our allow entry past 30 days. The UI is a little weird and you have to configure it as a Deny entry in order for the date fields to appear. Once you switch the entry back to Allow the date fields disappear but they still apply.

My question is this; how many auth attempts are necessary for the blacklist feature to block an IP? And how do I pull this information out of the system? I'm not seeing the failed auth attempts anywhere in the logs. A while back I set my debugging verbosity higher so I can use the log viewer for the files from "Generate Support Info" and I'm just not seeing anything.
 
15.5.15502.6 the default allow is +20 years for me. same as 16.0.3.676, the only time I have seen this is if you have something like noscript running on the browser.

I added 192.168.4.6 on both 15 and 16 as a test see attached.

You can change Authentication protection settings in
Settings > Security and change the auth attempts.

Other notes:
I have seen the public ip of access points with high latency like satellite internet get blacklisted from use of the 3cx phone on ios devices and it was just high latency.

Best of luck.
 

Attachments

  • 15-a.png
    15-a.png
    27.1 KB · Views: 2
  • 16-a.png
    16-a.png
    25.7 KB · Views: 2
Hello,

I am guessing you are switching the blacklisted IP to allow which is causing the entry to expire. This is happening because although you switch the action from Deny to allow the timer remains for that entry.
Delete the entry all together and add the IP in the list as allow from the beginning. This will ensure that the IP remains allowed.

As to what is causing the IP to be blacklisted this is something that you could troubleshoot by running a capture on the PBX and filtering with the providers IP.
The security settings can be found in Settings / Security Settings.
 
Thank you for the response. I was able to find the number of auth attempts. The only thing I don't have a good answer for is where in the logs those failed auth attempts would be. I did packet captures with the provider this morning and they're saying that there is no auth attempt. When I look at call packet captures it looks normal. I was hoping to find the bad auth attempts in the support log but I'm just not seeing it.

As for the adding a allow entry when I open the form and choose allow it still makes the date fields dissapear and defaults to 30 days. It's the same whether I use Brave or Opera. Not a big deal since I know how to work around it. We'll upgrade to 16 in the future so hopefully that will fix it.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,822
Members
164,813
Latest member
divdigital