Vitelity trunk: too many failed authentications problem

Leo_B

Silver Partner
Basic Certified
Joined
Nov 23, 2020
Messages
104
Reaction score
22
Hello y'all,

An interesting situation occurred Thursday morning: our 3CX v20 (Update 7) stopped accepting incoming calls. Instead of connecting, callers received busy tones, and there were no entries in the PBX logs. The Vitelity-configured SIP trunk showed as "Registered," and outbound calls were working without issue.

Ultimately, the problem was traced to the PBX blacklisting the Vitelity server IP address 64.2.142.90 due to "too many failed authentications." We’ve never encountered anything like this before:

Screenshot 2025-10-30 153331.png

The question is: does anyone have any ideas about what could have triggered such a stream of failed authentication attempts? Vitelity support stated: "We wouldn't be the ones to initiate such a communication. 64.2.142.90 will never send you any messages that would require authentication. Not for any reason."
 
Hello Leo_B,

We did encounter something like this as well about a year ago.
We found that the reason for our blacklist was an update at provider side, during the update the registration was not working and it triggered a blacklist somehow.
Meaning that the blacklist can initiate both ways.
Normally you would expect it to be an incomming request to be wrong and trigger the blacklist, but actually found that outgoing requests with multiple errors can also trigger a blacklist.
This would mean, that you can also have some error in the 3CX trunk setup ??? or multiple trunk setup with same IP ???
Not sure if this information will help you, but please check the 3CX SIP trunks.

Paulo
 
We normally allow list the SIP trunk IPs to avoid this sort of thing. Just be careful to add them as allow as IIRC deny is the default.
 
Guys, thank you all so much for your responses! Followed your advise and whitelisted Vitelity server on 3CX systems we manage. Now, here’s the next part of the story: I noticed that right before the Vitelity IP was blacklisted, the logs recorded several warnings labeled “Unidentified Incoming Call.” Vitelity support commented on this as follows:

Please see the attached HTML file, it covers the entirety of the call in question. You are challenging us for Authentication. You cannot do that. You need to disable Authentication on inbound calls.

Failed-Call.jpg


The problem is that I can’t find an option for “Authentication on inbound calls” in the 3CX v20 trunk settings. Any ideas?
 
I have addressed the ticket you submitted to 3CX Technical Support. The issue relates to the log you provided in the ticket; the problem seems to be more closely linked to Unidentified Incoming Call. Review INVITE and adjust source identification:.

This happens when the DID entered in the To SIP field of the invite header of the inbound call does not match the DID set under the trunks settings.
 
  • Like
Reactions: YiannisH_3CX

Latest Posts

Members Online Now

Forum statistics

Threads
111,831
Messages
589,276
Members
164,660
Latest member
RJenkinsROCK