RustPBX Basics: Hardening a Public PBX — the First 48 Hours

M
Miuda Team
Building conversational AI tooling

A PBX with a public IP gets scanned within minutes of going live. SipVicious and its cousins register-probe every open 5060 on the internet, hunting for default passwords they can turn into toll-fraud. Here’s the hardening checklist for the first 48 hours — all of it built in, none of it requiring external tooling.

1. ACL: Decide Who May Talk

Access control is evaluated on inbound trunk paths — internal extension-to-extension calls skip it:

acl_rules = [
    "allow 10.0.0.0/8",
    "allow 203.0.113.5",     # carrier egress
    "deny 0.0.0.0/0",
]

Deny-by-default costs five minutes and eliminates registration probing from unexpected sources.

2. The Scanner Blacklist

0.5 ships a built-in User-Agent blacklist with substring matching — SipVicious, sipvicious, friendly-scanner and friends are rejected at the door before they reach auth:

No configuration needed; it’s on by default. Your own ACL rules layer on top.

3. Frequency Limits

Registration and invite floods are rate-limited per source. Offenders get blocked automatically and the block list is inspectable:

GET  /ami/v1/frequency_limits    # list active blocks
DELETE /ami/v1/frequency_limits  # clear them

Watch the list during incident response — abnormal blocking patterns are your earliest intrusion signal.

4. Trunk-Level Trust

SIP trunk configuration with auth and IP controls

Per-trunk allowed_ips pin each carrier to its egress addresses; anything else claiming to be that trunk is dropped. Combined with challenge-response auth on register-enabled trunks, credential stuffing loses its surface.

5. Encryption Limits Interception

  • TLS on the SIP listener for carrier and extension signaling
  • SRTP (DTLS for WebRTC, SDES negotiated on SIP legs) for media
  • Topology hiding on the SBC path — internal addresses never leak into SDP headers

6. The Console Is Also a Target

  • Strong admin passwords, MFA if Enterprise Auth is enabled
  • console.allow_registration = false once your users exist
  • API tokens instead of shared sessions for automation, each with minimal scopes
  • Access logs shipped off-box (AccessLogEventFormat) so an attacker can’t tidy up

7. Fail Loudly

Business rejections log at WARN while protocol noise is suppressed — so when something IS wrong, the log window is readable instead of a firehose. Feed /health and the frequency-limit list into your alerting, and the first 48 hours become boring. That’s the goal.

The 48-Hour Checklist, Compressed

WhenAction
Hour 1ACL deny-by-default + carrier allowlist; disable console registration after creating users
Hour 2Verify UA blacklist is rejecting scanners (log line per reject)
Day 1Frequency limits tuned; alerting on /health + block list growth
Day 2TLS on SIP + console; SRTP forced on trunks that support it; review first week’s blocked sources before relaxing anything

More: the SBC guide and Security & compliance.

Get new posts by email

Deep dives on Rust telephony, contact centers and wholesale voice. No spam.

Thanks — you're on the list.

We use cookies for anonymous analytics to improve the site. Nothing is loaded until you accept. Privacy Policy