ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Securing FreePBX from attacks

    IT Discussion
    freepbx 14 freepbx security network security
    10
    67
    7.8k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender @EddieJennings
      last edited by

      @eddiejennings said in Securing FreePBX from attacks:

      Current task is now figuring what "invalid data" is being sent by my external test users to cause the firewall to think they're attackers.

      ug.. I have this exact problem!

      1 Reply Last reply Reply Quote 0
      • EddieJenningsE
        EddieJennings
        last edited by

        To clarify, this is negatively affecting people from making calls with Linphone. I'll deal with UCP access and such later. 😛

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller @EddieJennings
          last edited by

          @eddiejennings said in Securing FreePBX from attacks:

          Current task is now figuring what "invalid data" is being sent by my external test users to cause the firewall to think they're attackers.

          UDP?

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @scottalanmiller
            last edited by

            @scottalanmiller said in Securing FreePBX from attacks:

            @eddiejennings said in Securing FreePBX from attacks:

            Current task is now figuring what "invalid data" is being sent by my external test users to cause the firewall to think they're attackers.

            UDP?

            In @Dashrender's case he has Yealink desk phones as the only thing on site and the site is getting blacklisted by the responsive firewall. As soon as he white lists the IP, the phones register.

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @JaredBusch
              last edited by

              @jaredbusch said in Securing FreePBX from attacks:

              @scottalanmiller said in Securing FreePBX from attacks:

              @eddiejennings said in Securing FreePBX from attacks:

              Current task is now figuring what "invalid data" is being sent by my external test users to cause the firewall to think they're attackers.

              UDP?

              In @Dashrender's case he has Yealink desk phones as the only thing on site and the site is getting blacklisted by the responsive firewall. As soon as he white lists the IP, the phones register.

              Oh, the RP not the outside edge firewall. Odd, okay.

              EddieJenningsE 1 Reply Last reply Reply Quote 1
              • EddieJenningsE
                EddieJennings @scottalanmiller
                last edited by

                @scottalanmiller said in Securing FreePBX from attacks:

                @jaredbusch said in Securing FreePBX from attacks:

                @scottalanmiller said in Securing FreePBX from attacks:

                @eddiejennings said in Securing FreePBX from attacks:

                Current task is now figuring what "invalid data" is being sent by my external test users to cause the firewall to think they're attackers.

                UDP?

                In @Dashrender's case he has Yealink desk phones as the only thing on site and the site is getting blacklisted by the responsive firewall. As soon as he white lists the IP, the phones register.

                Oh, the RP not the outside edge firewall. Odd, okay.

                Yeah. Forgive my lack of clarity.

                1 Reply Last reply Reply Quote 0
                • EddieJenningsE
                  EddieJennings
                  last edited by

                  Other oddity. Both redacted IP addresses are the same.
                  0_1506611443310_c7d77dea-7939-4b8f-82e2-21494c9d39ce-image.png

                  DashrenderD zachary715Z 2 Replies Last reply Reply Quote 0
                  • DashrenderD
                    Dashrender @EddieJennings
                    last edited by Dashrender

                    @eddiejennings said in Securing FreePBX from attacks:

                    Other oddity. Both redacted IP addresses are the same.
                    0_1506611443310_c7d77dea-7939-4b8f-82e2-21494c9d39ce-image.png

                    Open another tab in chrome or whatever browser and type
                    What is my IP to confirm the expected IP.

                    EddieJenningsE 1 Reply Last reply Reply Quote 0
                    • EddieJenningsE
                      EddieJennings @Dashrender
                      last edited by EddieJennings

                      @dashrender said in Securing FreePBX from attacks:

                      @eddiejennings said in Securing FreePBX from attacks:

                      Other oddity. Both redacted IP addresses are the same.
                      0_1506611443310_c7d77dea-7939-4b8f-82e2-21494c9d39ce-image.png

                      Open another tab in chrome or whatever browser and type
                      What is my IP to confirm the expected IP.

                      Heh. Yes, I've confirmed the IP of the client machine mentioned is the IP I'm using, which is the IP that's assigned to the Trusted zone. 🙂

                      1 Reply Last reply Reply Quote 0
                      • zachary715Z
                        zachary715 @EddieJennings
                        last edited by

                        @eddiejennings said in Securing FreePBX from attacks:

                        Other oddity. Both redacted IP addresses are the same.
                        0_1506611443310_c7d77dea-7939-4b8f-82e2-21494c9d39ce-image.png

                        I think I had this happen when I set up mine. Everything seemed to work fine, but the error message was still there. I can't remember if it was a simple reboot that fixed it, a firmware upgrade, or what.

                        1 Reply Last reply Reply Quote 0
                        • EddieJenningsE
                          EddieJennings
                          last edited by

                          As a test, I added one of my remote end user's IP addresses to the System Admin > Intrusion Detection Whitelist to see if that would prevent them from being blocked by the Responsive Firewall. Alas, I return from lunch and they're once again blocked. Since I'm still in a testing mode, I'm thinking of blowing away this PBX, rebuilding, and seeing if the problem replicates.

                          DashrenderD 1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender @EddieJennings
                            last edited by

                            @eddiejennings said in Securing FreePBX from attacks:

                            As a test, I added one of my remote end user's IP addresses to the System Admin > Intrusion Detection Whitelist to see if that would prevent them from being blocked by the Responsive Firewall. Alas, I return from lunch and they're once again blocked. Since I'm still in a testing mode, I'm thinking of blowing away this PBX, rebuilding, and seeing if the problem replicates.

                            I'm curious to find out - since I'm having the same issue!

                            1 Reply Last reply Reply Quote 0
                            • EddieJenningsE
                              EddieJennings
                              last edited by

                              New PBX is now installed, configured, and updated. Let's see what happens.

                              1 Reply Last reply Reply Quote 0
                              • SmithErickS
                                SmithErick
                                last edited by

                                Might be time to play with the built-in OpenVPN server. I have RF enabled on my remote FreePBX with 90% of endpoints being Yealink and have not had any issues.

                                1 Reply Last reply Reply Quote 0
                                • DashrenderD
                                  Dashrender
                                  last edited by

                                  I wonder what Eddie and I are doing differently than JB that's causing our issues?

                                  1 Reply Last reply Reply Quote 0
                                  • JaredBuschJ
                                    JaredBusch
                                    last edited by

                                    Assuming you have reinstalled and the problem exists, open a support case with Sangoma. The cost is minimal compared to the time you are spending.

                                    1 Reply Last reply Reply Quote 0
                                    • EddieJenningsE
                                      EddieJennings
                                      last edited by

                                      Yeah. I'm probably going to have to do that. It just doesn't make sense for these Linphone users to successfully register, then be rate-limited, then be blocked as attackers.

                                      DashrenderD 1 Reply Last reply Reply Quote 0
                                      • DashrenderD
                                        Dashrender @EddieJennings
                                        last edited by

                                        @eddiejennings said in Securing FreePBX from attacks:

                                        Yeah. I'm probably going to have to do that. It just doesn't make sense for these Linphone users to successfully register, then be rate-limited, then be blocked as attackers.

                                        Only your soft phones are doing this?

                                        JaredBuschJ 1 Reply Last reply Reply Quote 0
                                        • JaredBuschJ
                                          JaredBusch @Dashrender
                                          last edited by

                                          @dashrender said in Securing FreePBX from attacks:

                                          @eddiejennings said in Securing FreePBX from attacks:

                                          Yeah. I'm probably going to have to do that. It just doesn't make sense for these Linphone users to successfully register, then be rate-limited, then be blocked as attackers.

                                          Only your soft phones are doing this?

                                          @EddieJennings this.. Do you not have a deskphone at one of these locations causing the same problem?

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @JaredBusch
                                            last edited by

                                            @jaredbusch said in Securing FreePBX from attacks:

                                            @dashrender said in Securing FreePBX from attacks:

                                            @eddiejennings said in Securing FreePBX from attacks:

                                            Yeah. I'm probably going to have to do that. It just doesn't make sense for these Linphone users to successfully register, then be rate-limited, then be blocked as attackers.

                                            Only your soft phones are doing this?

                                            @EddieJennings this.. Do you not have a deskphone at one of these locations causing the same problem?

                                            Both softphones and deskphones are causing my issue.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 3 / 4
                                            • First post
                                              Last post