What are the AWS ACL requirements

Status
Not open for further replies.

greychain

Gold Partner
Advanced Certified
Joined
Jul 13, 2018
Messages
779
Reaction score
122
I am hosting a 3CX site on an AWS EC2, the customer wants to allow only certain IP addresses to be able to connect to the server.

Now the SSL cannot renew.

What are the 3CX associated addresses I need to allow on the inbound rules to allow SSL to renew?

I opened all the ports just to allow for cert renewal and tried to manually renew using pbxconfigtool -renew-certificates but that did not seem to work. Automatic renewal did occur.
 
You would want to check on letsencrypt.org as that is who handles the certificates.
 
I was hoping 3CX would also list their addresses as with the locked down ACL the firewall test fails.
 
If you search in the forums, 3CX has stated many times that they use DNS and not IP addresses. They way they are architected the IP addresses could change. But passing the firewall checker is a different topic than what you originally asked about but the fix is the same. If you all you want is the green check box, then disable the rules, run the checker and then enable the rules again.
 
  • Like
Reactions: Evolute IT
For most 'maintenance' operations each 3CX installation only requires unrestricted outbound communication, so for License Activation, Cert Renewal, downloading of firmwares/templates, etc, no port forwarding is required.

In order to get unimpeded functionality of the 3CX features though, you need to make sure the following ports are open/forwarded: https://www.3cx.com/docs/ports/
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru