Author Topic: Mitel 250 connecting to unrecognized addresses  (Read 721 times)

Offline andyring

  • Jr. Member
  • **
  • Posts: 32
  • Country: us
  • Karma: +1/-0
    • View Profile
Mitel 250 connecting to unrecognized addresses
« on: September 10, 2020, 03:09:42 PM »
Hello all,

I regularly monitor the firewall at my office. We have a Mitel 250 with SIPs provided by our ISP, if that matters.

I regularly see outbound connection attempts from the phone system to IP addresses I don't recognize. Does anyone else recognize these? Is the phone system attempting to make legitimate connections?

Code: [Select]
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:35488    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:48817    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:43942    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:38707    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:41217    212.70.149.4:113 
mitel Unknown
TCP-S     192.168.0.9:55201       1.179.231.219:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:36729    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:46927    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:53222    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown
TCP-S     192.168.0.9:50158    212.70.149.4:113 
mitel Unknown
UDP     192.168.0.9:5060    37.49.229.237:5060 
mitel Unknown


Offline acejavelin

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 4064
  • Country: us
  • Karma: +129/-0
  • High-tech, heavy metal redneck!
    • View Profile
    • Like what I do and wanna help out? Send me a donation!
Re: Mitel 250 connecting to unrecognized addresses
« Reply #1 on: September 10, 2020, 09:16:31 PM »
Check with your SIP provider, but my guess is going to be those are alternate IP for RTP or other services for 37.49.229.237...

212.70.149.4:113 is IDENT lookup to LACNIC, which is the Internet Address Registry of Latin America and the Caribbean, odd, but not likely malicious.


 

Sitemap 1 2 3 4 5 6 7 8 9 10