User Tools

Site Tools


voice:pbx:freepbx:freepbx_firewall

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
voice:pbx:freepbx:freepbx_firewall [2021/03/11 09:43]
gcooper
voice:pbx:freepbx:freepbx_firewall [2024/02/06 09:27] (current)
gcooper
Line 1: Line 1:
 ====== FreePBX Security ====== ====== FreePBX Security ======
 +
 +**Background**: https://www.freepbx.org/a-secure-freepbx-is-a-happy-freepbx/
 +
 +**Pro Tips Video**: https://www.youtube.com/watch?v=CD_k5PrY7Xc
 +
 +**Setup Guide**: https://www.freepbxhosting.com/comprehensive-freepbx-firewall-setup-guide/
  
 ===== Safe Mode ===== ===== Safe Mode =====
  
-<note important>With Safe Mode enabledif you **reboot the PBX twice in five minutes** time, the **firewall rules activation will be delayed by five minutes** to allow an admin to fix his access problem.</note>+<note important>Safe Mode is enabled if you **reboot the PBX twice in five minutes** time
 + 
 +The **firewall rules activation will be delayed by five minutes** to allow an admin to fix the access problem.</note>
  
 ===== Firewall ===== ===== Firewall =====
Line 13: Line 21:
 **FreePBX -> Connectivity -> Firewall -> Settings (tab) -> Re-Run Wizard** **FreePBX -> Connectivity -> Firewall -> Settings (tab) -> Re-Run Wizard**
  
-Whitelist Host? -> **Yes** +  * Whitelist Host? -> **Yes** 
-Whitelist Network? -> **No** +  Whitelist Network? -> **No** 
-Enable Responsive Firewall? -> **Yes** +  Enable Responsive Firewall? -> **Yes** 
-Automatically configure Asterisk IP Settings? -> **Yes**+  Automatically configure Asterisk IP Settings? -> **Yes**
  
 **FreePBX -> Connectivity -> Firewall -> Networks (tab)** **FreePBX -> Connectivity -> Firewall -> Networks (tab)**
  
-:!: Overrides the default permission for an interface+:!: This tab overrides the default permission for an interface.
  
-**Trusted** -> Only add trusted **admin** IP, network or FQDN +  * **Trusted** -> Only add trusted **admin** IP, network or FQDN 
-**Local** -> Add IP, network or FQDN for **normal voice traffic** (where phones are)+  **Local** -> Add IP, network or FQDN for **normal voice traffic** (where phones are)
  
 **FreePBX -> Connectivity -> Firewall -> Interfaces (tab)** **FreePBX -> Connectivity -> Firewall -> Interfaces (tab)**
  
 +:!: This tab sets the **Default Traffic Zones**.
 +
 +  * You must set at least one interface as **Internet**
 +  * Single-interface systems will be set as **Internet** (''eth0'')
 +  * ''Trusted'' means **no filtering** at all
 +
 +**FreePBX -> Connectivity -> Firewall -> Responsive Firewall (tab)**
 +
 +  * Enable for any protocol in use
 +  * This will open ports for limited access
 +  * Too many failures will result in that IP being blocked
 +
 +**FreePBX -> Connectivity -> Firewall -> Intrusion Detection (tab)**
  
 +  * Shows blocked IPs
 +  * You can whitelist IPs or networks
  
 ===== Older Suggested Firewall Example ===== ===== Older Suggested Firewall Example =====
voice/pbx/freepbx/freepbx_firewall.1615480984.txt.gz · Last modified: 2021/03/11 09:43 by gcooper