Firewall installation
A properly configured firewall in front of your PBX, with a default-deny posture and only the ports your service genuinely needs left open.
Overview
Put a SIP service on a public IP and the scans start almost immediately — automated tools sweeping the internet for open ports, then working through common extension numbers and weak passwords. This is not targeted. It is constant background noise that finds anything left open.
When it succeeds the damage is financial and fast. A compromised PBX gets used to dial premium-rate international destinations, usually overnight and over a weekend, and the first anyone notices is the bill. Recovery is slow and the money is rarely recoverable.
We install and configure firewalls with tight access control lists, SIP-aware rules and brute-force protection, so your PBX is reachable by your trunks, your sites and your staff — and by nobody else. Then we set spend limits and destination restrictions as a second line of defence.

What's included
Layered, so a single failure does not become an incident.
A properly configured firewall in front of your PBX, with a default-deny posture and only the ports your service genuinely needs left open.
Explicit allow-lists for your trunk providers, office IPs and remote sites, so unknown sources are dropped before they reach the SIP stack.
Automatic banning of hosts that hammer SIP registration, cutting off credential-guessing attacks before they find a weak extension.
Destination restrictions and balance-based spend caps, so even a successful intrusion cannot run up an unlimited bill overnight.
Strong per-extension secrets, disabled defaults and removal of the unused test accounts that so often survive an install.
Firewall rules revisited as your estate changes, because the allow-list written eighteen months ago rarely matches who needs access today.
FAQ
You are not targeted personally — that is the point. The scanning is automated and indiscriminate, so a five-extension system on a public IP gets found just as quickly as a large one. Small businesses are often hit harder because nobody is watching the account overnight.
Not when it is configured by somebody who understands SIP and RTP. Badly configured firewalls cause one-way audio and dropped calls, which is exactly why generic IT rule sets so often fail on voice traffic.
Yes, and it is a common request. We audit the current rules, extension credentials and exposure, then give you a prioritised list of what to fix — you can have us do the work or hand it to your own team.
Contact us as a priority. The immediate steps are cutting outbound access to premium destinations, rotating every credential and identifying the entry point. We can help you work through that and then close the gap properly.
Related
Premium UK termination on Pay As You Go terms, billed per second.
Geographic and mobile numbers delivered over SIP to your PBX.
On-premises or cloud builds, fully configured and documented.
Multi-level menus, time conditions and routing built around your team.
Fast, responsive, search-friendly sites built by the same team.
We will review your current firewall rules and extension security and tell you plainly what needs fixing first.