FreePBX 17: SIP trunk provider gets rate limited and eventually blocked by firewall. How can I prevent this?

Context:
This is my first FreePBX 17 setup, 100% pjSIP. My other FreePBX system (around 100 of them) are all FreePBX 16 with a mix of chanSIP (for the trunks) and pjSIP (for the phones)

On the FreePBX 17, the SIP trunk provider IP address gets added to the Rate Limited Hosts as soon as the first call comes in. Eventually the IP gets added to the blocked Attackers list so the trunk gets disconnected. The IP of the SIP trunk provider is in the whitelist (Intrusion Detection)

I can’t find the cause for now. Seems like the logs are not helping me.

Is there a way to adjust fix this ? I don’t really know where to start… I saw some threshold settings (Tier1, Tier2, etc) but I’m a bit lost with them. I’m trying to find some documentation.

@chrischevy - You should simply add the IP into the firewall networks section in the local or trusted zone. This should allow it to skip the responsive firewall and calls should work at this point without any issues.

It is always best practice to add the ITSP IPs as mentioned, but the responsive firewall should be aware of the trunk IPs and not block them. You can always report this as a bug or open up a support case at http://help.sangoma.com/ to have support debug this further. As the configuration/logs need to be fully reviewed to confirm if its a bug or configuration issue.

1 Like

Yeah that’s what I did… but I never had to do this before. It will probably be the solution for the future installations.

1 Like