RalphF

New Member
Joined
Jul 7, 2016
Messages
5
Reaction score
1
Hi,
I have been running Asterisk and various flavors of PIAF, Trixbox, etc since Ward lived here in Atlanta. I turned John Mullinax (RIP) on to the platform many years ago and he went on to somewhat of an Asterisk "Celebrity", or at least he become well known, and actually ended up helping me out a lot as he gained much more experience than me. (For you Hams out there, I was his "Elmer" in Ham Radio and he was my local repeater trustee. I lost a great friend!)

I have been rocking along 10 years with some ancient versions running on a couple of servers in a CoLo facility. I lagged in upgrading them until there was really no path other than start new. So I spun up a couple in the cloud. Now I'm needing help and there is no John Mullinax to turn to. :-(


This particular PBX is running asterisk 11.18.0 incredible gui 12.0.30 (but I think it upgraded to 12.0.70). It is on ubuntu 14.04.2 lts. I'm posting here in PIAF 3 and hope this is the correct location.

Item 1: Service observing. There is a feature called Service Observing that was in many commercial PBXs, which allowed a supervisor to silently monitor (and break in to help) users or agent's calls. In the olden days, we had Chanspy and I thought there was a command someplace to use it. However now I can find no way for a supervisor to use this function. Can anyone tell me how to implement this now?

Item 2: Port Knocking, Travelin Man, or whatever the correct term is: I can't seem to keep remote static IPs able to access the system without timing out and knocking again. I must be misunderstanding the procedure to add them. These are ATAs and Soft Phones in remte locations. Somehow I did manage to keep the hard IP phones logged in. And to reiterate, the remote IPs are also static so I don't think there's a problem there.

When I installed, I received this message:

"WARNING: Server access locked down to server IP address and your current IP address.
Modify /etc/iptables/rules.v4 as needed and restart IPtables BEFORE logging out!
To restart IPtables, issue command: iptables-restart"

When I add those IPs to the file and restart IPtables, I would expect it to become permanent. However I then use iptables -L command and don't see the new entries. I see some entries that I must have entered somehow before but not the new ones. And I have to keep knocking...

Could someone please help me with the correct, reliable procedure to add these addresses so they will stay, otherwise I will have to really downgrade my security.

Thanks you very much!

Ralph
 

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,206
Reaction score
5,226
Hi Ralph,

Welcome back! The firewall setup depends upon whether your remote ATAs and softphones have dynamic IP addresses. If so, you'll need to set up dynamic FQDN updates through a provider and then use /root/add-fqdn to add those FQDNs on your PBX. If they are static IP addresses, you can simply use the IP addresses and add them to the firewall with /root/add-ip. I would choose option 0 to enable all services if these are people you know and trust.

ChanSpy is still around. Start here.
 

BostonDan

Member
Joined
Jul 9, 2017
Messages
32
Reaction score
5
Ralph,

Travelin' Man works great for me. It does require FQDN (as stated by Ward above) and Dynamic DNS (I use duckdns so I can connect my softphone on my cell phone and always answer calls to my house no matter where I am located).

Port Knocking is separate from Travelin' Man (I use travelin' man 3). Port Knocking will open the port for the IP that "knocks' at the port. It can be time sensitive (e.g. timeout after 60 seconds, etc.). I do not think you would want to keep the port open, even if it is to your own IP as your IP could change and without a reboot, the port stays open to whomever gets that IP (as far as I understand). Travelin' Man will open the port, but constantly check to see if you still have that IP (as long as you set up refresh using the crontab, so you check every minute, 10 minutes, etc.) and will only point to the IP you have at the time it checks.

If you need assistance in setting anything up, feel free to let me know.

Cheers,
B.D.
 

Members online

Forum statistics

Threads
25,821
Messages
167,814
Members
19,247
Latest member
mdauck
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Top