Windows client blacklisted repeatedly

Status
Not open for further replies.

whiteym

Gold Partner
Advanced Certified
Joined
Apr 16, 2020
Messages
23
Reaction score
9
Hi All,
Not sure if this belongs in the server section or here, I have a device/user which constantly gets blacklisted.
For the logs below the device was in the office, logged in but locked. I have truncated the logs to only show lines with the offending IP otherwise it's very chatty.
This is from the management console, not sure if there is a better one to look at.

2022/07/12 05:39:22.581|31601|0042|Inf|MYPHONE: 1ST Login User:2530, Password:null, SessionID:7ced4cd7-df70-dc2c-ac8d-224840d9f697, IP:172.30.1.100, ClientInfo:3CX Windows8 Phone ver.16.3.0.264, ClientVersion:16.3.0.264
2022/07/12 05:39:22.618|31601|0051|Inf|MYPHONE: 2ND Login User:2530, Password:<some long string>, SessionID:7ced4cd7-df70-dc2c-ac8d-224840d9f697, IP:172.30.1.100
2022/07/12 05:39:22.618|31601|0051|Inf|MYPHONE: Client 2530(172.30.1.100) with SessionId 7ced4cd7-df70-dc2c-ac8d-224840d9f697 has been added
2022/07/12 05:39:23.483|31601|0042|Inf|MYPHONE: 1ST Login User:2530, Password:null, SessionID:28925080-8d30-3135-4f95-20d85c08133e, IP:172.30.1.100, ClientInfo:3CX Windows8 Phone ver.16.3.0.264, ClientVersion:16.3.0.264
2022/07/12 06:32:54.087|31601|0046|Err|MYPHONE: SessionId: 7ced4cd7-df70-dc2c-ac8d-224840d9f697 (IP: 172.30.1.100): Request 'RequestServerTime' without logging in
2022/07/12 07:32:54.407|31601|0039|Err|MYPHONE: SessionId: 7ced4cd7-df70-dc2c-ac8d-224840d9f697 (IP: 172.30.1.100): Request 'RequestServerTime' without logging in
2022/07/12 07:38:24.367|31601|0068|Err|MYPHONE: SessionId: 7ced4cd7-df70-dc2c-ac8d-224840d9f697 (IP: 172.30.1.100): Request 'RequestServerTime' without logging in
2022/07/12 08:32:55.238|31601|0041|Err|MYPHONE: SessionId: 7ced4cd7-df70-dc2c-ac8d-224840d9f697 (IP: 172.30.1.100): Request 'RequestServerTime' without logging in
2022/07/12 08:32:55.238|31601|0041|Err|MYPHONE: IP 172.30.1.100 is blacklisted

The anti-hacking settings are on the default values.

I assume the 4 requests before the blacklist are the cause as they occur every time prior but I don't know how to fix it. Checking the firewall logs the client was making 443 and 5090 connections all night

Has anyone seen this before?
 
What error is also mentioned in the event log? additionally, check the windows app on the PC with Ip address 172.30.1.100, remove all its accounts and close it down (exit), remove the blacklisted IP address and open the app, check under the phones section of the management console, and locate the new PNP request from the app from the PC with IP 172.30.1.100, select it and assign it to the extension, Monitor and see if this issue re occurs, make sure also that the logging level of the system is in verbose logging mode so to get the max amount of info within the logs.
 
What error is also mentioned in the event log? additionally, check the windows app on the PC with Ip address 172.30.1.100, remove all its accounts and close it down (exit), remove the blacklisted IP address and open the app, check under the phones section of the management console, and locate the new PNP request from the app from the PC with IP 172.30.1.100, select it and assign it to the extension, Monitor and see if this issue re occurs, make sure also that the logging level of the system is in verbose logging mode so to get the max amount of info within the logs.
I set logging to verbose then got the user to reproduce the issue, the event log didn't show anything when I searched for the IP (I'm not sure what file on disk is the event log).
After I remove the IP from the blacklist the app starts working immediately and won't break again for the rest of the day (and sometimes several days). The app only has a single account listed and I have tried removing the account and re-adding it.
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur