Yealink Ghost Calls

Status
Not open for further replies.

Alphabetic

3CX MVP
Silver Partner
Advanced Certified
Joined
Jul 1, 2016
Messages
6,540
Reaction score
2,567
Hi Guys,

after port forwarding to my STUN extension we're getting ghost calls.

Can you please tell me which template (if any) the W52P uses so I can amend it to disable direct SIP?

Thanks!
 
Hello @kieferschild

There are other actions you can take to prevent these calls from happening. The first is settings with the phone a unique SIP port and locking it down from the firewall to accept requests only from the Public IP of the PBX. If this is not possible then you can assign the phone an unusual high SIP port through the management console so it is not scanned and reprovision the device so the new port is applied.
 
Hi Yiannis,

Their firewall is pretty rubbish. Is the remote port 3CX uses also the local SIP port or does 3CX come to the STUN phone on another?

Also, shouldnt the "allow direct IP - disable" sort this?

Thanks,
 
Yealink have got these on their website:
http://support.yealink.com/faq/faqInfo?id=559
http://support.yealink.com/faq/faqInfo?id=181

However as @YiannisH_3CX has already stated you need to lock down your firewall ASAP as well as looking at settings on the PBX (block country codes for example) and on the ITSP SIP trunk.

You will find that most reputable ITSP's will have mechanisms that can both inform you of when scamming is in place as well as rules to limit the amount and type of outbound call allowed.

Most of these types of calls will be trying to call high premium lines to rack up a lot of calls.
 
  • Like
Reactions: YiannisH_3CX
Is the remote port 3CX uses also the local SIP port or does 3CX come to the STUN phone on another?
Each STUN enabled phone should have a unique port that is used for the communication with the PBX. This port is configurable under the DECT phones settings. The PBX will use that port to communicate with that phone (the port should be forwarded on the remote sites firewall).
The tools that generate these ghost calls scan specific port ranges so if you use a high sip port value then the phone will not be found by these tools.

The option you are looking for is already disabled by default in the 3CX provided templates since V15. So if you are using a version prion to that i would recommend upgrading to the latest version
 
Hi Edd,

thanks for the reply.

my SIP provider is IP restricted to accept the 3CX WAN IP anyway so i'm not concerned with that.

we've just got a W52P handset that's getting ghost calls from 1001 every couple of minutes.

I've done the "disable direct IP" from the phones and i will look to lock down the firewall.
 
Each STUN enabled phone should have a unique port that is used for the communication with the PBX. This port is configurable under the DECT phones settings. The PBX will use that port to communicate with that phone (the port should be forwarded on the remote sites firewall).
The tools that generate these ghost calls scan specific port ranges so if you use a high sip port value then the phone will not be found by these tools.

The option you are looking for is already disabled by default in the 3CX provided templates since V15. So if you are using a version prion to that i would recommend upgrading to the latest version

Hi Yiannis,

weirdly enough the T23G template I was using from 3CX wasnt disabling that option and i'm on the latest SP and FW.

I will create a firewall rule that accepts 5065 from 3CX PBX to 5065 to local IP of the phone.

thanks again.
 
Glad i could assist
 
use an SBC and avoid the firewall woes entirely. Raspiberry Pi 3 is super cheap...
 
Status
Not open for further replies.

Forum statistics

Threads
111,886
Messages
589,561
Members
164,752
Latest member
017