RustPBX Basics: Hardening a Public PBX — the First 48 Hours
A PBX with a public IP gets scanned within minutes of going live. SipVicious and its cousins register-probe every open 5060 on the internet, hunting for default passwords they can turn into toll-fraud. Here’s the hardening checklist for the first 48 hours — all of it built in, none of it requiring external tooling.
1. ACL: Decide Who May Talk
Access control is evaluated on inbound trunk paths — internal extension-to-extension calls skip it:
acl_rules = [
"allow 10.0.0.0/8",
"allow 203.0.113.5", # carrier egress
"deny 0.0.0.0/0",
]
Deny-by-default costs five minutes and eliminates registration probing from unexpected sources.
2. The Scanner Blacklist
0.5 ships a built-in User-Agent blacklist with substring matching — SipVicious, sipvicious, friendly-scanner and friends are rejected at the door before they reach auth:
No configuration needed; it’s on by default. Your own ACL rules layer on top.
3. Frequency Limits
Registration and invite floods are rate-limited per source. Offenders get blocked automatically and the block list is inspectable:
GET /ami/v1/frequency_limits # list active blocks
DELETE /ami/v1/frequency_limits # clear them
Watch the list during incident response — abnormal blocking patterns are your earliest intrusion signal.
4. Trunk-Level Trust

Per-trunk allowed_ips pin each carrier to its egress addresses; anything else claiming to be that trunk is dropped. Combined with challenge-response auth on register-enabled trunks, credential stuffing loses its surface.
5. Encryption Limits Interception
- TLS on the SIP listener for carrier and extension signaling
- SRTP (DTLS for WebRTC, SDES negotiated on SIP legs) for media
- Topology hiding on the SBC path — internal addresses never leak into SDP headers
6. The Console Is Also a Target
- Strong admin passwords, MFA if Enterprise Auth is enabled
console.allow_registration = falseonce your users exist- API tokens instead of shared sessions for automation, each with minimal scopes
- Access logs shipped off-box (
AccessLogEventFormat) so an attacker can’t tidy up
7. Fail Loudly
Business rejections log at WARN while protocol noise is suppressed — so when something IS wrong, the log window is readable instead of a firehose. Feed /health and the frequency-limit list into your alerting, and the first 48 hours become boring. That’s the goal.
The 48-Hour Checklist, Compressed
| When | Action |
|---|---|
| Hour 1 | ACL deny-by-default + carrier allowlist; disable console registration after creating users |
| Hour 2 | Verify UA blacklist is rejecting scanners (log line per reject) |
| Day 1 | Frequency limits tuned; alerting on /health + block list growth |
| Day 2 | TLS on SIP + console; SRTP forced on trunks that support it; review first week’s blocked sources before relaxing anything |
More: the SBC guide and Security & compliance.