- Mitglied seit
- 13. März 2021
- Beiträge
- 266
Hallo,
bei einem Telekom SIP Trunk mit on-premise 3cx (Windows 10 mit Version 15.5) könnten die Watchguard Firewall Regeln / Policies gehärtet werden.
Es sind keine IP Tischtelefone ausserhalb des LANs vorhanden.
Die Smartphone App und der 3cx Webclient wird von Deutschland aus verwendet.
Diese Seite ist bei dem Thema vermutlich wichtig: https://www.3cx.com/docs/ports/
Ziel: keine 3cx Alerts mehr mehr und Firewall Policy Sicherheit "härten"
IP xxx.xxx.xxx.xx has been blacklisted on PBX firma.3cx.de SIP Server/Call Manager
Ziel2: Watchguard Policy Geolocation (lizenzpflichtig) Funktion verwenden, weil 3cx Webclient nur von Deutschland aus verwendet wird
Ziel3: in der Watchguard Policy limitieren, dass VOIP / SIP nur mit dem dem Telekom SIP Trunk erlaubt ist:
reg.sip-trunk.telekom.de und transport-tcp.sip-trunk.telekom.de
vorher, die zwei Watchguard Policies sehen aktuell noch so aus:
from: any-external
to: lokale IP der 3cx (geht bei watchguard mit SNAT Funktion)
5060 TCP
5060 UDP
5090 UDP
5090 TCP
9000-10999 UDP
48000-65535 UDP
5000-5001 TCP
5061 TCP
+++
ausgehend ist bei Watchguard alles erlaubt, d.h. diese Policy ist m.A. nach eigentlich überflüssig:
from: lokale IP der 3cx
to: any-external
5001 TCP
443 TCP
5015 TCP
5060-5061 TCP
5090 TCP
5060 UDP
5090 UDP
48000-65535 UDP
9000-10999 UDP
4443 TCP
+++++
FRAGE:
Ist es richtig das die neue "eingehende" Policy so sein müsste?
(wenn man keine externen IP Tischtelefone jedoch 3cx Smartphoe App, Webmeeting und 3cx Webclient für Telefonie gelegentlich von Deutschland aus verwenden möchte?
Besten dank vorab!
NEU ENTWURF:
from:
reg.sip-trunk.telekom.de
transport-tcp.sip-trunk.telekom.de
to: lokale IP der 3cx (geht bei watchguard mit SNAT Funktion)
5060 TCP
5060 UDP
5090 UDP
5090 TCP
9000-10999 UDP
48000-65535 UDP
5061 TCP
+++
++++++
from: any-external (aber nur Deutschland mittels Watchguard Geolocation Funktion)
to: lokale IP der 3cx (geht bei watchguard mit SNAT Funktion)
5000-5001 TCP (3cx Webclient im Chrome)
++++
SIP Server/Call Manager
IP xxx.xxx.xxx.xxx has been blacklisted on PBX firmenname.3cx.de.
Affected Module: SIP Server/Call Manager
The IP 107.xxx.xx.148 has been blacklisted for 86400 seconds. (Expires at: 2021/05/02 00:07:58).
Reason: Too many failed authentications! This IP Address has made numerous attempts to authenticate with 3CX with invalid authentication details. Therefore a blacklist rule has been created denying this IP to continue sending requests.
To delete this rule, login to the 3CX Management console > Dashboard > IP Blacklist. Enter this IP Address 107.150.95.148 in the search field and delete the entry.
You can whitelist the IP or you can permanently block this IP or the whole subnet it belongs to.
Visit this url for more information on black/white listing https://www.3cx.com/docs/allow-deny-ip-addresses/
bei einem Telekom SIP Trunk mit on-premise 3cx (Windows 10 mit Version 15.5) könnten die Watchguard Firewall Regeln / Policies gehärtet werden.
Es sind keine IP Tischtelefone ausserhalb des LANs vorhanden.
Die Smartphone App und der 3cx Webclient wird von Deutschland aus verwendet.
Diese Seite ist bei dem Thema vermutlich wichtig: https://www.3cx.com/docs/ports/
Ziel: keine 3cx Alerts mehr mehr und Firewall Policy Sicherheit "härten"
IP xxx.xxx.xxx.xx has been blacklisted on PBX firma.3cx.de SIP Server/Call Manager
Ziel2: Watchguard Policy Geolocation (lizenzpflichtig) Funktion verwenden, weil 3cx Webclient nur von Deutschland aus verwendet wird
Ziel3: in der Watchguard Policy limitieren, dass VOIP / SIP nur mit dem dem Telekom SIP Trunk erlaubt ist:
reg.sip-trunk.telekom.de und transport-tcp.sip-trunk.telekom.de
vorher, die zwei Watchguard Policies sehen aktuell noch so aus:
from: any-external
to: lokale IP der 3cx (geht bei watchguard mit SNAT Funktion)
5060 TCP
5060 UDP
5090 UDP
5090 TCP
9000-10999 UDP
48000-65535 UDP
5000-5001 TCP
5061 TCP
+++
ausgehend ist bei Watchguard alles erlaubt, d.h. diese Policy ist m.A. nach eigentlich überflüssig:
from: lokale IP der 3cx
to: any-external
5001 TCP
443 TCP
5015 TCP
5060-5061 TCP
5090 TCP
5060 UDP
5090 UDP
48000-65535 UDP
9000-10999 UDP
4443 TCP
+++++
FRAGE:
Ist es richtig das die neue "eingehende" Policy so sein müsste?
(wenn man keine externen IP Tischtelefone jedoch 3cx Smartphoe App, Webmeeting und 3cx Webclient für Telefonie gelegentlich von Deutschland aus verwenden möchte?
Besten dank vorab!
NEU ENTWURF:
from:
reg.sip-trunk.telekom.de
transport-tcp.sip-trunk.telekom.de
to: lokale IP der 3cx (geht bei watchguard mit SNAT Funktion)
5060 TCP
5060 UDP
5090 UDP
5090 TCP
9000-10999 UDP
48000-65535 UDP
5061 TCP
+++
++++++
from: any-external (aber nur Deutschland mittels Watchguard Geolocation Funktion)
to: lokale IP der 3cx (geht bei watchguard mit SNAT Funktion)
5000-5001 TCP (3cx Webclient im Chrome)
++++
SIP Server/Call Manager
IP xxx.xxx.xxx.xxx has been blacklisted on PBX firmenname.3cx.de.
Affected Module: SIP Server/Call Manager
The IP 107.xxx.xx.148 has been blacklisted for 86400 seconds. (Expires at: 2021/05/02 00:07:58).
Reason: Too many failed authentications! This IP Address has made numerous attempts to authenticate with 3CX with invalid authentication details. Therefore a blacklist rule has been created denying this IP to continue sending requests.
To delete this rule, login to the 3CX Management console > Dashboard > IP Blacklist. Enter this IP Address 107.150.95.148 in the search field and delete the entry.
You can whitelist the IP or you can permanently block this IP or the whole subnet it belongs to.
Visit this url for more information on black/white listing https://www.3cx.com/docs/allow-deny-ip-addresses/