  • If the Com.X is accessing external VoIP trunks via a NAT router/firewall, no special port forwarding is required. If external VoIP agents (e.g. SIP phones) need to access the Com.X, forward only ports 5060 and 10000-20000 to the Com.X for VoIP control and voice communication.

  • Configure the firewall to block all incoming VoIP traffic except that from a white-list of remote extensions.

  • Ensure that all VoIP extensions and trunks have strong (generated) passwords, different from the extension number.

  • Activate fail2ban