<div dir="ltr">You need to use one or more apply-inbound-acl to allow access via ACLs you have created.<div><br></div><div>If you don&#39;t supply apply-inbound-acl then the default will be loopback.auto, to lock access down to local access only.<div><br></div><div>In 1.2 the default was to not apply any ACL (allow anyone), in 1.4 it requires you to be explicit or it&#39;ll only allow local connections even if you listen on 0.0.0.0 or ::. This is more secure.</div><div><br></div><div>If you&#39;re opening it up to remote access you want to be very careful about who you allow to connect. The protocol is unencrypted, the password is sent in plaintext, and it provides the ability to crash freeswitch or execute system commands as the freeswitch user. So it&#39;s a security hole that you don&#39;t want to be any more open than it absolutely has to be.</div><div><br></div><div><br></div><div><div><br></div><div><br></div></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 11 September 2015 at 12:58, Pavel <span dir="ltr">&lt;<a href="mailto:my.post@hotmail.com" target="_blank">my.post@hotmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">


<div><div dir="ltr">Hello,<br> I was trying to enable esl connections from outside of fs host. To do so I&#39;ve followed <a href="https://wiki.freeswitch.org/wiki/Mod_event_socket#Configuration" target="_blank">https://wiki.freeswitch.org/wiki/Mod_event_socket#Configuration</a> and changed default event_socket.conf.xml<br>from:<div><br><div><div>&lt;configuration name=&quot;event_socket.conf&quot; description=&quot;Socket Client&quot;&gt;</div><div>  &lt;settings&gt;</div><div>    &lt;param name=&quot;nat-map&quot; value=&quot;false&quot;/&gt;</div><div>    &lt;param name=&quot;listen-ip&quot; value=&quot;::&quot;/&gt;</div><div>    &lt;param name=&quot;listen-port&quot; value=&quot;8021&quot;/&gt;</div><div>    &lt;param name=&quot;password&quot; value=&quot;ClueCon&quot;/&gt;</div><div><span style="font-size:12pt">  &lt;/settings&gt;</span></div><div>&lt;/configuration&gt;</div><div><br>to:</div><div><br></div><div><div>&lt;configuration name=&quot;event_socket.conf&quot; description=&quot;Socket Client&quot;&gt;</div><div>  &lt;settings&gt;</div><div>    &lt;param name=&quot;nat-map&quot; value=&quot;false&quot;/&gt;</div><div>    &lt;param name=&quot;listen-ip&quot; value=&quot;0.0.0.0&quot;/&gt;</div><div>    &lt;param name=&quot;listen-port&quot; value=&quot;8021&quot;/&gt;</div><div>    &lt;param name=&quot;password&quot; value=&quot;ClueCon&quot;/&gt;</div><div><span style="font-size:12pt">  &lt;/settings&gt;</span></div><div>&lt;/configuration&gt;</div></div><div><br>and issued: </div><div>reload mod_event_socket.<br><br>Trying to telnet to fs host on port 8021 I observe:<br><br><div>Content-Type: text/rude-rejection</div><div>Content-Length: 24</div><div><br></div><div>Access Denied, go away.</div><div>Content-Type: text/disconnect-notice</div><div>Content-Length: 67</div><div><br></div><div>Disconnected, goodbye.</div><div>See you at ClueCon! <a href="http://www.cluecon.com/" target="_blank">http://www.cluecon.com/</a></div><div>Connection closed by foreign host.</div><div><br></div>And in fs log i can see the following:<br><br>mod_event_socket.c:2603 IP &quot;someiphere&quot; Rejected by acl &quot;loopback.auto&quot;<br><br>But as far as I understand the <span style="font-size:12pt">event_socket.conf.xml doesn&#39;t mention any ACL set up against ESL connection ?</span></div><div>Would someone please be so kind to point what am I missing ?</div><div>Thanks.</div><div>Regards,</div><div>Pavel.</div><div><span style="font-size:12pt"><br></span></div><div><br></div><br></div></div>                                               </div></div>
<br>_________________________________________________________________________<br>
Professional FreeSWITCH Consulting Services:<br>
<a href="mailto:consulting@freeswitch.org">consulting@freeswitch.org</a><br>
<a href="http://www.freeswitchsolutions.com" rel="noreferrer" target="_blank">http://www.freeswitchsolutions.com</a><br>
<br>
Official FreeSWITCH Sites<br>
<a href="http://www.freeswitch.org" rel="noreferrer" target="_blank">http://www.freeswitch.org</a><br>
<a href="http://confluence.freeswitch.org" rel="noreferrer" target="_blank">http://confluence.freeswitch.org</a><br>
<a href="http://www.cluecon.com" rel="noreferrer" target="_blank">http://www.cluecon.com</a><br>
<br>
FreeSWITCH-users mailing list<br>
<a href="mailto:FreeSWITCH-users@lists.freeswitch.org">FreeSWITCH-users@lists.freeswitch.org</a><br>
<a href="http://lists.freeswitch.org/mailman/listinfo/freeswitch-users" rel="noreferrer" target="_blank">http://lists.freeswitch.org/mailman/listinfo/freeswitch-users</a><br>
UNSUBSCRIBE:<a href="http://lists.freeswitch.org/mailman/options/freeswitch-users" rel="noreferrer" target="_blank">http://lists.freeswitch.org/mailman/options/freeswitch-users</a><br>
<a href="http://www.freeswitch.org" rel="noreferrer" target="_blank">http://www.freeswitch.org</a><br></blockquote></div><br></div>