Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.



49 posts

Geek


Topic # 89638 6-Sep-2011 16:25 Send private message

Okay, so 3CX have released a new version (v10) of their Windows-based IPPBX software and it is clearly supposed to support 3-way-auth.
This is something that a lot of VFX users have been waiting for right?
Interestingly, I can register for outgoing as in the previous versions, but not for incoming.

I'm still playing around at this stage and hope to get something for people but if there's anyone out there who has used v10 and successfully registered for both incoming and outgoing calling then their input would be a great help to the community.3-way-auth


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
2869 posts

Uber Geek
+1 received by user: 131

Trusted
Subscriber

  Reply # 517647 6-Sep-2011 17:16 Send private message

Ah this is really interesting. My understanding is 3cx is much more user friendly than existing VOIP PBXs?





3551 posts

Uber Geek
+1 received by user: 60

Trusted
WorldxChange

  Reply # 517649 6-Sep-2011 17:18 Send private message

Well that is good news, send us some info and we can see what it is happening




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications



49 posts

Geek


  Reply # 517652 6-Sep-2011 17:22 Send private message

Zeon: Ah this is really interesting. My understanding is 3cx is much more user friendly than existing VOIP PBXs?


Yes and no in my opinion. Just handed over a Cisco UC320W to a client who moved offices after the Feb EQ here in Chch and that was so easy the customer could (and probably should) have done the install.

Where I see 3CX fitting in well is for those small businesses who are running an old Windows SBS2003 or similar and already have one or two lines (no DVX) on WorldxChange's VFX network. Mainly because they don't need another box (linux or whatever) and the web management is pretty easy. Plus of course there's a free version that will suit a lot of small businesses with very few users or concurrent calls.

Still trying to get incoming to auth at the moment.

3551 posts

Uber Geek
+1 received by user: 60

Trusted
WorldxChange

  Reply # 517658 6-Sep-2011 17:27 Send private message

Yes the UC320 is excellent I did a lot of beta testing with Cisco on this and it's fully supported on DVX, really great easy to use product and auto provisons into voice and data vlans, as you point out the customer can drive this box, Cisco did a excellent job for this product

https://supportforums.cisco.com/docs/DOC-17937



https://supportforums.cisco.com/docs/DOC-15041




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications



49 posts

Geek


Reply # 517661 6-Sep-2011 17:33 Send private message

maverick:  Cisco did a excellent job for this product
Undecided
They sure did but I did see a lot of asterisk notes when looking at syslog info. But all that's beside the point - it's a great box that works well. I really don't care whose logo is on it if it works this well. Now if only they could make it do some of the things the Pomegranate NS08 does! (google it)

PS. Have PM'd you my details if you that helps.

3551 posts

Uber Geek
+1 received by user: 60

Trusted
WorldxChange

  Reply # 517666 6-Sep-2011 17:38 Send private message

kay ... first issue, turn off your PAP2 Wink




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications



49 posts

Geek


  Reply # 517668 6-Sep-2011 17:41 Send private message

maverick: kay ... first issue, turn off your PAP2 Wink


HAH! I didn't expect this to be an issue because I had the friendly guys in provisioning change my PAP2T's profile to be on the non-standard 8060 port about 2 or 3 months ago.

But it's a good point nonetheless and certainly worth trying anyway.

3551 posts

Uber Geek
+1 received by user: 60

Trusted
WorldxChange

  Reply # 517671 6-Sep-2011 17:45 Send private message

Working now :)




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications



49 posts

Geek


  Reply # 517673 6-Sep-2011 17:48 Send private message

Thanks Maverick - that did it. Which is fantastic and terrible at the same time.

Fantastic: Well obvious reasons there!
Terrible: How embarrassing that I didn't kill the PAP2T to start with
Not-so-bad: Would be good to have both the 3CX and PAP2T on the same connection using different ports.

Actually that's not an issue because in most situations (as in an earlier post) is for small businesses etc, and they'll not have multiple registrations so this was more of an exercise to see if 3CX version 10 works with the 3-way-auth.


Really sorry for wasting everyone's time!

3551 posts

Uber Geek
+1 received by user: 60

Trusted
WorldxChange

  Reply # 517678 6-Sep-2011 17:53 Send private message

You should be able to but not with the same credentials, the PAP2T was getting rejected as it it was not using the same details, these would have changed when you moved to openVFX, also they can not exist together with the same details and different ports as they will overwrite each other.

Really good to see that they have finally enabled 3way auth, was a pretty big oversight really and I was not prepared to jeopardize customer security but allowing these devices on the network without it.




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications



49 posts

Geek


  Reply # 517687 6-Sep-2011 18:03 Send private message

maverick: Really good to see that they have finally enabled 3way auth, was a pretty big oversight really and I was not prepared to jeopardize customer security but allowing these devices on the network without it.


Indeed it is! Given the number of attacks on SIP boxes these days and how easily attacks can be automated I completely agree with decisions of security over compatibility. Considering there's plenty of other options around? - now all the 3CX wishers will be happy.

Thanks also for the explanation of why things failed - Great to have that info in there in case someone else has this issue.

On the note of security, recently I had literally millions of failed Auth attempts from a Russian IP trying to get through while I was away - managed to use close to 70GB of my data in about a week.

russia

All of this traffic is SIP 5060 UDP traffic - so just like FTP, as soon as you open up a port - be prepared to be attacked on it!




3551 posts

Uber Geek
+1 received by user: 60

Trusted
WorldxChange

  Reply # 517694 6-Sep-2011 18:16 Send private message

Yep .... thats why Asterisk is such a dangerous platfom for home users I'm afraid, they are not going to know they are getting attacked or hacked untill the bill comes, really most users do not know how to secure their devices properly unfortunatly




Yes I am a employee of WxC (My Profile) ... but I do have my own opinions as well Wink

             

https://www.facebook.com/wxccommunications



49 posts

Geek


  Reply # 517695 6-Sep-2011 18:22 Send private message

maverick:  do not know how to secure their devices properly unfortunatly


Well I'm glad you guys do! Wink
After all, you're protecting your customers by having extra security and policies to stick by - this is a good thing.

I guess I should close off this topic now and let you all go home. 


18577 posts

Uber Geek
+1 received by user: 738

Moderator
Trusted
Biddle Corp
Subscriber

  Reply # 517704 6-Sep-2011 18:49 Send private message

Was that hack attack against an Asterisk box? From my experience the attacks stop pretty quickly now once they stop seeing SIP responses, obviously the guys writing the bots are getting smarter (which is also good the for the end user) and then move on to another IP address. The good news with this it improves the effectiveness of fail2ban and iptables rules if you do need port 5060 wide open to the world.



49 posts

Geek


  Reply # 517722 6-Sep-2011 19:48 Send private message

sbiddle: Was that hack attack against an Asterisk box?


Ummm dare I say it? No, it was an attack on a 3CX VM. Happened while I was away and I was surprised I didn't get complaints from people complaining the internet was so slow considering the volume of traffic in such a short period of time I'd expect the internet to be a bit crappy.

3CX does ban IPs after a configurable number of fails but I guess in this case (where I was using a standard SIP port) they just kept on trying. I guess they get something for trying.

Still - it's all unwanted traffic nonetheless. Some things here is that using a decent Cisco 1801 router with Netflow we can see this sort of thing.

I'm imagining a home user and a SOHO router this sort of attack would really suck balls. Again - the importance of protecting people with limited knowledge. Protecting them from themselves as well as others with less honourable intentions. 

 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic








Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Telecom introduces unlimited broadband data plan
Created by freitasm, last reply by kawaii on 25-Apr-2014 04:42 (100 replies)
Pages... 5 6 7


Stonedine
Created by Lizard1977, last reply by mattwnz on 24-Apr-2014 15:45 (67 replies)
Pages... 3 4 5


Auckland Transport Hop card - look out for errors
Created by robjg63, last reply by sbiddle on 24-Apr-2014 20:48 (21 replies)
Pages... 2


Windows 8 System Mechanics
Created by eme, last reply by eme on 24-Apr-2014 21:10 (20 replies)
Pages... 2


Using my Mac to ring family in the UK
Created by Geektastic, last reply by nakedmolerat on 24-Apr-2014 11:28 (19 replies)
Pages... 2


Telecom has started metering their TiVo customers' broadband usage (WITHOUT PRENOTIFICATION)
Created by Peteriv, last reply by mattwnz on 24-Apr-2014 15:11 (74 replies)
Pages... 3 4 5


Forms of government for New Zealand
Created by charsleysa, last reply by gzt on 24-Apr-2014 21:36 (176 replies)
Pages... 10 11 12


Parallel imported product
Created by Wills1, last reply by joker97 on 23-Apr-2014 21:01 (53 replies)
Pages... 2 3 4



Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.