This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
voice:pbx:freepbx:freepbx_firewall [2016/12/14 10:07] gcooper |
voice:pbx:freepbx:freepbx_firewall [2024/02/06 09:27] (current) gcooper |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== FreePBX Security ====== | ====== FreePBX Security ====== | ||
- | **Responsive Firewall HowTo**: http://www.freepbxhosting.com/blog/how-to-freepbx-13-firewall-setup/ | + | **Background**: https://www.freepbx.org/a-secure-freepbx-is-a-happy-freepbx/ |
- | **Overview**: http://wiki.freepbx.org/display/ | + | **Pro Tips Video**: https://www.youtube.com/watch? |
- | **Getting Started**: http://wiki.freepbx.org/display/FPG/ | + | **Setup Guide**: https://www.freepbxhosting.com/comprehensive-freepbx-firewall-setup-guide/ |
- | **Permissions**: | + | ===== Safe Mode ===== |
- | **Responsive Firewall**: http://wiki.freepbx.org/ | + | <note important> |
- | ===== Safe Mode ===== | + | The **firewall rules activation will be delayed by five minutes** to allow an admin to fix the access problem.</ |
+ | |||
+ | ===== Firewall | ||
+ | |||
+ | **Basic Firewall Configuration - Watch First**: https:// | ||
+ | |||
+ | Run the **Firewall Wizard**: | ||
+ | |||
+ | **FreePBX -> Connectivity -> Firewall -> Settings (tab) -> Re-Run Wizard** | ||
+ | |||
+ | * Whitelist Host? -> **Yes** | ||
+ | * Whitelist Network? -> **No** | ||
+ | * Enable Responsive Firewall? -> **Yes** | ||
+ | * Automatically configure Asterisk IP Settings? -> **Yes** | ||
+ | |||
+ | **FreePBX -> Connectivity -> Firewall -> Networks (tab)** | ||
+ | |||
+ | :!: This tab overrides the default permission for an interface. | ||
+ | |||
+ | * **Trusted** -> Only add trusted **admin** IP, network or FQDN | ||
+ | * **Local** -> Add IP, network or FQDN for **normal voice traffic** (where phones are) | ||
+ | |||
+ | **FreePBX -> Connectivity -> Firewall -> Interfaces (tab)** | ||
+ | |||
+ | :!: This tab sets the **Default Traffic Zones**. | ||
+ | |||
+ | * You must set at least one interface as **Internet** | ||
+ | * Single-interface systems will be set as **Internet** ('' | ||
+ | * '' | ||
+ | |||
+ | **FreePBX -> Connectivity -> Firewall -> Responsive Firewall (tab)** | ||
+ | |||
+ | * Enable for any protocol in use | ||
+ | * This will open ports for limited access | ||
+ | * Too many failures will result in that IP being blocked | ||
+ | |||
+ | **FreePBX -> Connectivity -> Firewall -> Intrusion Detection (tab)** | ||
- | With Safe Mode enabled, if you reboot the PBX twice in five minutes time, the **firewall rules activation will be delayed by five minutes** to allow an admin to fix his access problem. | + | |
+ | | ||
===== Older Suggested Firewall Example ===== | ===== Older Suggested Firewall Example ===== |