Do I need to open up t*f*t*p (69) for external phones?

fishfilet

New Member
Joined
Mar 23, 2009
Messages
98
Reaction score
0
I will have a few external phones in my setup. Right now the phones inside download their config from t*f*t*p. I was wondering if I need to open up port 69 which is t*f*t*p i think on my router so that external phones can download their configs or is this a bad idea?

Also I am using polycom 601's right now. Is there anything special I need to do to make them work externally?
 
If you open t*f*t*p to the public, when your phones boot, they will phone home and if I am watching your traffic, I will have the required credentials to become one of your extensions. I think the only safe way to provision remote phones would be through dedicated bandwidth or a VPN, but not the open Internet.
 
I don't think it would even require watching the traffic. A t*f*t*p server open to the internet is one of the first things any security person shuts down. As soon as some interloper finds the t*f*t*p server open, he can simply download anything thats there. So the provisioning files (which DO contain all the info jmullinix describes) are there for the taking.

A more secure method is a must.

Jeff
 
Thank you I thought it seems very insecure but I wanted to make sure.
 
Is this only needed for provisioning? If so can I just provision the phones and then send them out to my remote users? I guess the only problem would be if I wanted to make any changes.
 

Members online

No members online now.

Forum statistics

Threads
26,687
Messages
174,411
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top