{"id":305628,"date":"2020-10-27T09:03:58","date_gmt":"2020-10-27T13:03:58","guid":{"rendered":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/?p=305628"},"modified":"2020-10-27T09:26:59","modified_gmt":"2020-10-27T13:26:59","slug":"8-actions-to-secure-your-phone-system-with-3cx","status":"publish","type":"post","link":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/8-actions-to-secure-your-phone-system-with-3cx\/","title":{"rendered":"8 Actions to Secure Your Phone System with 3CX"},"content":{"rendered":"\n<p>The rise of remote work has brought opportunities to hackers. VoIP Supply and 3CX co-host a monthly webinar to help our 3CXresellers stay on top of the latest updates\/ This month, we focused on the measures you can take to secure your phone system! Let\u2019s take a quick glance at the eight actions you can take immediately:<\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/www.voipsupply.com\/blog\/voip-insider\/files\/2020\/10\/8-actions-1024x576.png\" alt=\"\" class=\"wp-image-305638\" srcset=\"https:\/\/www.voipsupply.com\/blog\/voip-insider\/files\/2020\/10\/8-actions-1024x576.png 1024w, https:\/\/www.voipsupply.com\/blog\/voip-insider\/files\/2020\/10\/8-actions-150x84.png 150w, https:\/\/www.voipsupply.com\/blog\/voip-insider\/files\/2020\/10\/8-actions-300x169.png 300w, https:\/\/www.voipsupply.com\/blog\/voip-insider\/files\/2020\/10\/8-actions-768x432.png 768w, https:\/\/www.voipsupply.com\/blog\/voip-insider\/files\/2020\/10\/8-actions.png 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<a href=\"https:\/\/meetings.ipvideotalk.com\/114673978\/register\"><figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh5.googleusercontent.com\/0KxQwt5MMUiWBQOqvBkpLdo2_qCodyJyv5rjsv4n107uFvkBABrpeF1QRKp7ZS74ktM66Ue7j3saTsqVX_RZSmzrjsxRGznLwK32EHL4TVmDbzECz6fPbbjvJTg0ID4qwXhjEGAl\" alt=\"\"><\/figure><\/a>\n\n\n\n<p><a href=\"https:\/\/hubs.ly\/H0y5QDn0\">Download our 3CX webinar presentation slides to learn more!<\/a><\/p>\n\n\n\n<p>Snom also joined us to talk about their D120 and D7XX Series IP Phones and more. <a href=\"https:\/\/hubs.ly\/H0ybgSm0\">Click here to see the slides.<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>#1 SIP Authentication&nbsp;<\/strong><\/h2>\n\n\n\n<p>Setting up your SIP authentication is the first step! The default setting requires a random 10 character alphanumeric SIP ID and password; however, you can secure further with more characters (up to 50)&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>#2 Extension Security: Voicemail PIN&nbsp;<\/strong><\/h2>\n\n\n\n<p>Do you have PIN numbers for your voicemail? One you enable the default setting, you can set up a random 4-digits of numeric PIN and the system gives you 3 failed attempts. If you don\u2019t need voicemail at all, it\u2019s better to disable the function.&nbsp;<\/p>\n\n\n\n<p>You can also make your voicemail more secure by increasing the PIN digit length (up to 10)<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>#3 Extension Security: Security Settings&nbsp;<\/strong><\/h2>\n\n\n\n<p>Check out more security settings you can change to protect your system here:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Disable Extension for unused extensions&nbsp;<\/li><li>Disable External calls. Only internal calls possible&nbsp;<\/li><li>&nbsp;PIN Protect. Allow external calls only after entry of Voicemail PIN (Example: 777)&nbsp;<\/li><li>Prevent extensions from REGISTERing from outside the Local LAN&nbsp;<\/li><li>Prevent Apps from connecting from external locations through the tunnel&nbsp;<\/li><li>Block outbound calls outside office hours. Cleaners etc<\/li><\/ul>\n\n\n<h2><strong>#4 Allowed Country Codes&nbsp;<\/strong><\/h2>\n\n\n<p>Set allowed country codes to specify to which countries your calls are allowed to be made. Follow these steps:<\/p>\n\n\n\n<p>\u2192 Settings \u2192 Security \u2192 Allowed Country Codes&nbsp;<\/p>\n\n\n\n<p>\u2192 Specifies to which countries calls are allowed to be made&nbsp;<\/p>\n\n\n\n<p>\u2192 Uses International Dialing Code from E164 settings<\/p>\n\n\n\n<p>\u2192 Match after Outbound Rule reformatting&nbsp;<\/p>\n\n\n\n<p>\u2192 Must match exactly to be effective<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>#5 Configure Secure SIP&nbsp;<\/strong><\/h2>\n\n\n\n<p>\u2192 Settings \u2192 Security \u2192 Secure SIP&nbsp;<\/p>\n\n\n\n<p>\u2192 Certificates pre-configured for 3CX FQDNs&nbsp;<\/p>\n\n\n\n<p>\u2192 Provision telephones in sSIP mode (Manually)&nbsp;<\/p>\n\n\n\n<p>\u2192 Attention: Secure SIP uses TCP port 5061 (Default)&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>3CX App for Windows&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 Extension \u2192 Phone Provisioning \u2192 SIP Transport = TLS<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>#6 SRTP&nbsp;<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>Encryption of audio streams (RTP)&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 from and to an active extension&nbsp;<\/p>\n\n\n\n<p>\u2192 Using crypto keys&nbsp;<\/p>\n\n\n\n<p>\u2192 Must be activated on Extension &amp; IP Phone (useless without sSIP)&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Setup of sRTP IP Phones&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 Enable sRTP via the Web UI of Phones&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>3CX App for Windows&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 RTP Mode = Only Secure<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>#7 Anti-Hacking Options&nbsp;<\/strong><\/h2>\n\n\n\n<p>There are more anti-hacking actions you can take:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Failed Authentication Protection&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 Specify the amount of failed Authentication Attempts<\/p>\n\n\n\n<p>\u2192 Once Exceeded \u2192 Blacklisted&nbsp;<\/p>\n\n\n\n<p>\u25cb Default \u2192 25 attempts&nbsp;<\/p>\n\n\n\n<p>You can also secure your system further by reducing the number of attempts allowed (min 3). Just be careful that reducing too much may cause legitimate extensions to be Blacklisted!<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Failed Challenge Requests&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 Specify the amount of Unchallenged 407 Authentication Requests&nbsp;<\/p>\n\n\n\n<p>\u2192 Once Exceeded \u2192 Blacklisted&nbsp;<\/p>\n\n\n\n<p>The default gives you 1000 attempts but again, you can alter this number to reduce attempts allowed (min 100).<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Protects against packet floods&nbsp;<\/li><li>Split into 3 levels\/barriers&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 Below Amber = no action&nbsp;<\/p>\n\n\n\n<p>\u2192 Amber Barrier reached = 5 seconds (throttling)&nbsp;<\/p>\n\n\n\n<p>\u2192 Red Barrier reached = Blacklist interval&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Blacklist Time Interval&nbsp;<\/li><\/ul>\n\n\n\n<p>\u2192 Once IP is Blacklisted by Anti-Hacking Options&nbsp;<\/p>\n\n\n\n<p>\u2192 Remains Blacklisted for the number of seconds specified&nbsp;<\/p>\n\n\n\n<p>The default number is 86400 s (24 hrs). You can increase value upto a maximum of 1,000,000,000 s (~11,574 days or 31.7 years).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>#8 IP Blacklist&nbsp;<\/strong><\/h2>\n\n\n\n<p>Block out unwanted guests by adding their IP address to a blacklist:<\/p>\n\n\n\n<p>\u2192 Dashboard \u2192 IP Blacklist&nbsp;<\/p>\n\n\n\n<p>\u25cb When Anti-Hacking criteria are met&nbsp;<\/p>\n\n\n\n<p>\u2192 IPs of \u2018perpetrators\u2019 are added&nbsp;<\/p>\n\n\n\n<p>\u2192 Default Global Blacklist Time Interval&nbsp;<\/p>\n\n\n\n<p>You may also manually set up the Blacklist \/ Whitelist IPs to deny and\/or allow certain IPs.<\/p>\n\n\n\n<p>Ready to learn more? <a href=\"https:\/\/hubs.ly\/H0y5QDn0\">Download our Presentation Slides to Learn More Do\u2019s and Don&#8217;ts!<\/a> <a href=\"https:\/\/www.voipsupply.com\/manufacturer\/3cx\">Visit our 3CX product pages<\/a> or <a href=\"https:\/\/www.voipsupply.com\/manufacturer\/3cx\">visit VoIPSupply\u2019s 3CX Page<\/a> to get more information.<\/p>\n\n\n\n<p><a href=\"https:\/\/meetings.ipvideotalk.com\/114673978\/register\">Don\u2019t forget to register for our next 3CX reseller webinar! Click here to register today.<\/a><br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The rise of remote work has brought opportunities to hackers. VoIP Supply and 3CX co-host a monthly webinar to help our 3CXresellers stay on top of the latest updates\/ This month, we focused on the measures you can take to secure your phone system! Let\u2019s take a quick glance at the eight actions you can [&hellip;]<\/p>\n","protected":false},"author":123,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1223],"tags":[1058,1180],"class_list":["post-305628","post","type-post","status-publish","format-standard","hentry","category-voip-systems","tag-3cx","tag-snom"],"_links":{"self":[{"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/posts\/305628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/users\/123"}],"replies":[{"embeddable":true,"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/comments?post=305628"}],"version-history":[{"count":2,"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/posts\/305628\/revisions"}],"predecessor-version":[{"id":305640,"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/posts\/305628\/revisions\/305640"}],"wp:attachment":[{"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/media?parent=305628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/categories?post=305628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.voipsupply.com\/blog\/voip-insider\/wp-json\/wp\/v2\/tags?post=305628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}