So, just a few comments (and not 'fix' requests), since I'm running old and unsupported Cisco 7960 phones here..... and I'm really trying hard to make this not sound like a rant....it's not intended as one.
First, I REALLY wish 3CX had made this a major version update to make it clear how much was going to change. It's done now, of course, but even after reading the release notes and even being fully aware that I'm still running unsupported phones, I was not expecting some of the issues I am having, with the excellent track record that 3CX has for solid updates within a version.
Second, I didn't see anywhere it being mentioned that the Authentication ID and Authentication password length and strength were going to be ENFORCED by this update. I've been seeing the warning triangle in the admin console, but at least I was able to go in and change things without having to change the AuthID and AuthPW (with the 7960, of course, I have to also change this on the TFTP server and reboot the phone to pick up the configuration, and lately time has just been so tight....). If it was mentioned and I just missed it, that's on me, of course, but I did read through the blog and the Build History, and if it's there I just missed it. If I had known this was going to be the case, I would have rolled out the AuthID and PW changes first to all of our phones, tested that separately, and then updated....
Third, and possibly related to the second one, after the update I've had to add an allow rule for our internal networks in the blacklist configuration because all of the 7960's were hitting the blacklist with 'too many failed authentication attempts' even after making the AuthID and PW changes on the TFTP server for each phone's SIP configuration. Is there a setting in the logging to log the actual attempted credentials to aid in troubleshooting this? I really don't want a blanket whitelisting of our internal LAN for security reasons. Further, our Patton Electronics T1 VoIP gateway ALSO began periodically kicking the blacklist; I whitelisted it, too. Note that the phones all work, and unless blacklisted can all make outgoing calls; even with the Patton gateway being blacklisted we could receive calls over those trunks but only when it wasn't blacklisted. Admittedly, I'm behind on the firmware updates for the Patton, but it's still listed as supported.
Fourth, yes, I know the Cisco 7960 is legacy and not supported; I'm fully aware of that, and that's why I'm not asking for a 'fix' but just for help in finding out how to stretch the life of our installed base until I can afford to replace them all (we're a 501(c)(3) and run on a very tight budget, one that is already stretched by the annual support renewal).
And, last but not least, is there a reasonable rollback method to get back to what was working at Update 5? While I know that's a last resort thing, and wouldn't be recommended or supported, at the moment I have a very annoying phone system on my hands, with extensions continuing to ring for a long time even after a different extension has picked up, and an extension that is somehow hard-forwarding to the user's mobile number (she has both a 7960 deskphone and the iOS app on her iphone; even with the deskphone powered off this is happening and it is not configured in any of the forwarding rules). I took her extension off the ring group for now so that incoming calls can actually route to the IVR.
So sorry that this sounds like a rant; it's really not intended to be a rant, since I am fully aware that I'm running unsupported phones, and I have really liked 3CX over the years we've been customers. But since the update on Saturday I have been overwhelmed chasing these gremlins in what had been a very stable system.
Anyway, thanks for reading.
EDIT: While the event log does show invalid authentication attempts and the credentials that were attempted by those IP addresses, the ones I was seeing did not have that info. Here's an excerpt from the event log (note that all 10.x.y.z and 192.168.x.y addresses are internal to my campus network here):
Code:
...
The IP 192.168.1.139 has been blacklisted for 180 sec. (Expires at: 2023/02/21 11:12:07). Reason: Too many failed authentications!
SIP Server ID: 12290 02/21/2023 11:09:07 AM
The IP 10.1.130.144 has been blacklisted for 180 sec. (Expires at: 2023/02/21 11:11:22). Reason: Too many failed authentications!
SIP Server ID: 12290 02/21/2023 11:08:22 AM
User or password is invalid from 212.237.5.136. (User: 103, password: 000000000)
3CX Phone System Management Console ID: 30037 02/21/2023 11:08:22 AM
The IP 192.168.1.118 has been blacklisted for 180 sec. (Expires at: 2023/02/21 11:11:08). Reason: Too many failed authentications!
SIP Server ID: 12290 02/21/2023 11:08:08 AM
The IP 192.168.120.128 has been blacklisted for 180 sec. (Expires at: 2023/02/21 11:09:56). Reason: Too many failed authentications!
SIP Server ID: 12290 02/21/2023 11:06:56 AM
The IP 192.168.1.142 has been blacklisted for 180 sec. (Expires at: 2023/02/21 11:09:49). Reason: Too many failed authentications!
SIP Server ID: 12290 02/21/2023 11:06:49 AM
...