Solved 3CX and Teams have stopped communicating

Status
Not open for further replies.

DavidHodgson

Silver Partner
Basic Certified
Joined
Oct 22, 2021
Messages
62
Reaction score
16
We have 3CX setup with Teams, everything was working OK until yesterday morning.

I have logged into Teams Admin Portal and on the Direct Routing SBC, I have the following message...

"Inactive the trunk never connected" and "We monitor trunk connectivity every 15 seconds by using a Transport Layer Security (TLS) handshake, along with SIP Options monitoring. This trunk hasn’t attempted a TLS handshake in the last 15 minutes. To troubleshoot and fix: Check your Session Border Controller (SBC) certificate validity; check the trunk availability; check your network environment and firewall; and make sure that sending SIP options on the trunk are turned on."

3CX is hosted on Azure, port 5062 is open, certificate is valid until August 2022.

In 3CX the following appears in the Microsoft 365 Integration settings page "Secure SIP/TLS is required for Microsoft Teams Direct Routing", I think that has always been there and has not stopped Direct Routing working.

Running v18 of 3CX

Any ideas please?

Thanks
David
 
Hi David,

Yes, that always needed to be active, not sure how it got disabled if you didn't do it, but that's what the error suggests.

Go to Security --> Secure SIP and make sure:
  • Option is enabled
  • If you are using a Customer FQDN (not a 3CX one...), then make sure that the certificate is valid.
 
Hi David,

Yes, that always needed to be active, not sure how it got disabled if you didn't do it, but that's what the error suggests.

Go to Security --> Secure SIP and make sure:
  • Option is enabled
  • If you are using a Customer FQDN (not a 3CX one...), then make sure that the certificate is valid.
Secure SIP is turned off, we are using a 3CX FQDN so you issue the certificate. The two certificate boxes are empty.

Check the Secure SIP box and click OK, go back in and Secure SIP is disabled again.
 
Yes, this is because the 3 boxes were empty.

So what you need to do now is enable the option and fill the 2 boxes first.

Log into your 3CX Server via SSH and go to the following path:
/var/lib/3cxpbx/Bin/nginx/conf/Instance1/

Here you will see a few file, but you interested in only 2:
  • <your FQDN>-crt.pem
  • <your FQDN>-key.pem

Open them in a text editor and copy the contents over the "key.pem" file into the "Private Key" field, and the contents of the "crt.pem" file into the "Certificate" field.

Enable option, press OK, then you should be OK.
 
  • Like
Reactions: DavidHodgson
OK, will try that.

We deployed to Azure using the tool from the 3CX Customer Portal. I don't recall seeing any SSH credentials, how would I connect to this machine?

Thanks
 
I don't recall seeing any SSH credentials, how would I connect to this machine?
At the very end of the wizard, when it tells you that the machine has been deployed, there it also tells you the SSH credentials that were generated for the machine that was created.

To access via SSH though, check out the Note at the very end of Step 3:
https://www.3cx.com/docs/hosting-pbx-phone-system-microsoft-azure/#h.femvhunhhkpx

You need to manually add a Firewall Rule for port 22.
 
  • Like
Reactions: DavidHodgson
At the very end of the wizard, when it tells you that the machine has been deployed, there it also tells you the SSH credentials that were generated for the machine that was created.

To access via SSH though, check out the Note at the very end of Step 3:
https://www.3cx.com/docs/hosting-pbx-phone-system-microsoft-azure/#h.femvhunhhkpx

You need to manually add a Firewall Rule for port 22.
OK, I had copied those down. I have copied the CRT and PEM text to 3CX and enabled Secure SIP.

In the CRT file, there were two certificates (two Begin and End statements with hash between) am I right to copy both lots of text and put them into the certificate part of 3CX?

If so I have done that and still Teams shows the Direct Routing is down.
 
Ignore that the Direct Routing is now working
 
Excellent! Settings this to 'Solved'.
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK