VOIPNOX

Network security

Firewall Installation & ACL Configuration

VoIP systems get scanned within minutes of going live. We make sure the only traffic that reaches your PBX is traffic you asked for.

  1. Home
  2. Services
  3. Firewall & ACL Configuration

Overview

Your PBX is being probed right now

Put a SIP service on a public IP and the scans start almost immediately — automated tools sweeping the internet for open ports, then working through common extension numbers and weak passwords. This is not targeted. It is constant background noise that finds anything left open.

When it succeeds the damage is financial and fast. A compromised PBX gets used to dial premium-rate international destinations, usually overnight and over a weekend, and the first anyone notices is the bill. Recovery is slow and the money is rarely recoverable.

We install and configure firewalls with tight access control lists, SIP-aware rules and brute-force protection, so your PBX is reachable by your trunks, your sites and your staff — and by nobody else. Then we set spend limits and destination restrictions as a second line of defence.

ACL hardeningExplicit allow, default deny
Fraud mitigationDestination & spend limits
Ongoing reviewRules revisited as you change
Padlock resting on a circuit board representing network security

What's included

How we lock the platform down

Layered, so a single failure does not become an incident.

Firewall installation

A properly configured firewall in front of your PBX, with a default-deny posture and only the ports your service genuinely needs left open.

Access control lists

Explicit allow-lists for your trunk providers, office IPs and remote sites, so unknown sources are dropped before they reach the SIP stack.

Brute-force protection

Automatic banning of hosts that hammer SIP registration, cutting off credential-guessing attacks before they find a weak extension.

Toll-fraud limits

Destination restrictions and balance-based spend caps, so even a successful intrusion cannot run up an unlimited bill overnight.

Credential hygiene

Strong per-extension secrets, disabled defaults and removal of the unused test accounts that so often survive an install.

Rule review

Firewall rules revisited as your estate changes, because the allow-list written eighteen months ago rarely matches who needs access today.

FAQ

Questions about VoIP security

You are not targeted personally — that is the point. The scanning is automated and indiscriminate, so a five-extension system on a public IP gets found just as quickly as a large one. Small businesses are often hit harder because nobody is watching the account overnight.

Not when it is configured by somebody who understands SIP and RTP. Badly configured firewalls cause one-way audio and dropped calls, which is exactly why generic IT rule sets so often fail on voice traffic.

Yes, and it is a common request. We audit the current rules, extension credentials and exposure, then give you a prioritised list of what to fix — you can have us do the work or hand it to your own team.

Contact us as a priority. The immediate steps are cutting outbound access to premium destinations, rotating every credential and identifying the entry point. We can help you work through that and then close the gap properly.

Related

Other services we provide

UK DIDs

Geographic and mobile numbers delivered over SIP to your PBX.

IVR Solutions

Multi-level menus, time conditions and routing built around your team.

Web Development

Fast, responsive, search-friendly sites built by the same team.

Find out what your PBX is exposing

We will review your current firewall rules and extension security and tell you plainly what needs fixing first.

Chat on WhatsApp