I am also looking for some settings to stop external devices from registering with my PBXs... or, at least trying to. Since March 2nd, two of the three 3CX PBXs I monitor are getting hammered. I went from less than a dozen entries in the Blacklisted IPs to almost 2 pages. Their activity log (in verbose) shows a lot of repeat (already blacklisted or banned) IPs, and I still see roughly 7 or 8 unique IPs per day trying to authenticate as various IP phones or PBXs.
I haven't yet figured out what port(s) I can block without stopping my legitimate soft phones from remotely logging in. So, far they are just stand-alone PBXs... no bridges, SBCs, etc. I think I have cranked down the 3CX Security settings to "excessively anal", but I haven't found anything to thwart the attempts.
As an old security-oriented IT person, I prefer to not give *them* the opportunity. I am also still learning to secure these PBX units. I am hoping to find something I can do besides turning off notifications and ignoring these failed attempts. I don't want to leave a potential success route.
I am looking for a better hardening option, and I haven't been able to isolate the routers as a potential weakness. I am hoping someone can point out an obvious thing I am not recognizing.
For those curious about the routers in question:
. Two of the routers I am connected to are Cisco RV320s. They need to be replaced, but one of them have not be on the attack vector while they are on adjacent IP addresses. I think they are set the same, except the one getting hammered is a test unit and doesn't have 5060/5061 defined for a SIP provider.
. The third 3CX is on a Cisco RV160 and has assigned the SIP provider, and it is getting hammered just as badly as the RV320 mentioned. These units don't have VPN configured, but the one that is NOT getting hammered does.
. I am thinking about building up a pfSense+ device, but am currently resource restricted.
Thank you in advance for any helpful information to point me in the correct direction!