Setup
Security
The firewall and address blocking, who can reach what, extension passwords, toll fraud protection and the attack log.
For PBX version 0.3 (alpha)
Protection settings are in “System” → “Security”. Everyone can see this page; the administrator can change it. Its tabs: “Firewall”, “Toll fraud protection”, “Passwords and login”, “Attack log”.
Firewall
The PBX itself blocks addresses from which a wrong password is entered many times in a row.
- “Protection level” — “Weak”, “Normal”, “Strong” or “Maximum”: the higher the level, the fewer attempts before a block and the longer the block. The exact numbers are in “Advanced”; “Defaults” brings back the standard ones.
- “Watch only” — the PBX does not block anyone, it only shows whom it would have blocked. On a new PBX this mode is on for the first day.
- “Blocked now” — the list of blocked addresses. The “Unblock” button lifts a block, for example if an employee mistyped the password on their phone.
- “Never block” — addresses that are never blocked: for example, the office address.
Who can reach what
In “Who can reach what”, you choose from which networks — the internet, the office, phones, VPN, providers — SIP and audio, the panel, SSH and other services can be reached.
- “Only known phones from the Internet” — from the internet, only phones that have already worked with the PBX can connect. Employees who travel then need a VPN.
- After “Apply”, the PBX waits 120 seconds for the “Everything works” confirmation. If access to the panel is lost and you cannot confirm, the previous settings come back by themselves.
Do not open the panel and SSH to the whole internet unless you need to: keep access from the office and over VPN.
Extension passwords
The “Passwords and login” tab, in the “Extension passwords” block, shows weak SIP passwords: shorter than 12 characters, the same as the extension number, or from the list of common passwords.
- “Change” or “Change all weak” — set new random passwords. The new passwords are shown once: enter them in the phones, or the phones will stop connecting.
- “A random password for new extensions” — new extensions get a strong password right away.
- “Do not save an extension with a weak password” — the panel will not let you save an extension with a weak password.
One more protection is “Allowed networks” in the extension settings: from which addresses its phone may connect. For office phones, enter the office network.
Toll fraud protection
If an extension’s password falls into the wrong hands, someone can make calls to expensive destinations through the PBX. The protection limits such calls:
- “Limits” — how many external calls and minutes are allowed;
- “Dangerous directions” — “Allowed”, “With PIN” or “Forbidden” for expensive directions; “Protection PIN” is the code for them;
- “When a limit is crossed” — “Only warn”, “Block the number” or “Stop every external call”.
If the protection has tripped, the panel shows a warning, and the “Tripped in 30 days” list shows what happened. Check the extension and change its password, then click “Unblock the number” or “Resume external calls”.
Attack log
The “Attack log” tab shows failed attempts to sign in to SIP, the panel and SSH: from which addresses and for what reason. The log is kept for 90 days; you can download it with the “Download CSV” button.
Your password and backups
- Make the panel administrator’s password long and use it only for the panel.
- Set a PIN for the server console menu: “General settings” → “Server console”.
- Encrypt backups with a password and keep that password separately: Backups.