Vicidial behind PfSense - dynamic remote agent IP Whitelist

All installation and configuration problems and questions

Moderators: gerski, enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, Michael_N

Vicidial behind PfSense - dynamic remote agent IP Whitelist

Postby xtdirect » Tue Dec 09, 2014 11:50 am

Install Information:
Standalone
Vicibox redux 32bit preload 3.1.15
VERSION: 2.6-372a
BUILD: 120713-2123
Sangoma CPD
All sip g729

Issue:
We have been happily using vicidial behind the latest PfSense firewall without issue for years..
Because we have agents that log in from home, we have a fair number of users that do not have a static IP address.
For this reason our firewall approach has been to keep a watchful eye and blacklist offending IP with PfBlocker to aid in the task.

Recently, however we have been crushed with attacks attempting to log into our asterisk servers…..

Ideally we want to whitelist, but need an automated way to allow at home agents to log in when their IP changes.

In PfSense there is a way to create an Alias that contains whitelisted IPs, however it only updates once a day.

I built a solution that would require the at home agent to authenticate to a website which would ssh into the PfSense box and update the Alias whitelist with the new IP address, but it does not constantly allow the traffic after the update… so the solution is not effective.

I have also considered using Fail2ban, but know the pitfalls and potential to have legitimate traffic get blocked by a stupid user…. Whitelisting is what I am after...

What is the best way to accomplish this task?

VPN adds a level of complexity to the agents, as well as processing overhead and requires updating as agents come and go..

ANY suggestions are greatly appreciated….

Thanks!!
hwdevelopment.com
xtdirect
 
Posts: 23
Joined: Wed Jul 25, 2012 1:02 pm

Re: Vicidial behind PfSense - dynamic remote agent IP Whitel

Postby rrb555 » Tue Dec 09, 2014 11:34 pm

One server that I am managing | Single Server | ViciBox Redux 6.0 | VERSION: 2.12-549a | BUILD: 160404-0940 | revision 2508| No other hardware
For help you can send me a direct email info@support.com.ph
rrb555
 
Posts: 585
Joined: Tue Feb 08, 2011 4:24 pm
Location: Quezon City, Philippines

Re: Vicidial behind PfSense - dynamic remote agent IP Whitel

Postby xtdirect » Wed Aug 12, 2015 1:52 pm

I wrote my own real time authentication gateway for pfSense.
Here is a link to an overview of how it was done:
http://www.hwdevelopment.com/blog/20-real-time-pfsense-whitelisting-application-using-coldfusion
hwdevelopment.com
xtdirect
 
Posts: 23
Joined: Wed Jul 25, 2012 1:02 pm


Return to Support

Who is online

Users browsing this forum: Bing [Bot] and 56 guests