Community discussions

MikroTik App
 
User avatar
Techsystem
Member
Member
Topic Author
Posts: 354
Joined: Tue Dec 21, 2021 5:12 am

Security issue with DST NAT rules

Thu Apr 25, 2024 6:17 am

Hi Mikrotik people there..!
do you think that creating a DST NAT rule in MikroTik is considered to be a security vulnerability in the router?
I mean Today my 3CX installer set up the 3CX software on my server. Then, he opened 10 ports on my MikroTik router, arguing that this is necessary for the system to work. Does it make sense to leave 10 ports open in this way without any proplem in the future..?
 
User avatar
jvanhambelgium
Forum Veteran
Forum Veteran
Posts: 998
Joined: Thu Jul 14, 2016 9:29 pm
Location: Belgium

Re: Security issue with DST NAT rules

Thu Apr 25, 2024 8:24 am

https://www.3cx.com/docs/manual/firewal ... iguration/

Apparently for this SIP-provider there seems to be quite some stuff you need to open and they don't mention any of their public IP's / FQDN's of their SBC's....
I guess it depends on the SIP-provider.
I have seen installations that only required OUTBOUND connection to the cloud-provider, no toying around with any DNAT mappings you have to make etc. (and no upnp in scope, this is a corporate environment)

However, if you can make the DNAT combined with ACCESS-LIST to only whitelist the IP's from 3CX that enhanced the level of security already a lot?
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19542
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Security issue with DST NAT rules

Thu Apr 25, 2024 4:45 pm

Zero trust cloudflare tunnel removes the need to open port is you can run it.
Best bet is to create a source address list of allowed IPs, which renders ports invisible on scans, otherwise they are visible but closed on scans.
Any server you have open should be encrypted access in some way shape or form.

I have a sip modem, to connect to my VOIP provider and no ports and no port forwarding are required.

Who is online

Users browsing this forum: bitx0, GoogleOther [Bot], Kingdres1 and 26 guests