Solved 3CX App not ringing

Status
Not open for further replies.

meepman

New User
Joined
Feb 15, 2021
Messages
2
Reaction score
1
Good morning all,

I setup a 3cx in AWS and have my soft phone connected to it I can make outbound calls but it's not ringing for incoming calls.

On my PC it works just fine I have no issues with incoming calls not ringing it's just on the mobile app.

I have my NACLS setup to allow inbound access to:

TCP - 5060, 5090,5061, 5001, 443, 2195-2197, 5228-5230
UDP - 5060, 5090, 9000-10999

Outbound: Allow all

When I allow all inbound traffic in the NACL it works fine with no issue but I also don't want to leave all ports open on it for security purposes.

My question is what port am I missing because I cannot find it anywhere
 
Hey @meepman

The ports required by 3CX are indeed the ones you specified. I'm just not sure about TCP 2197-2197 and TCP 5228-5230, why are those forwarded?

Also, both 443 and 5001 should not be required, only one of the two is your HTTPS port, you could check on which port you can reach the Management Console (https://abc.3cx.com:5001 or https://abc.3cx.com:443) and that would be your HTTPS port.

Regarding the issue you're facing, you should keep the following in mind:

When a call is made to a Mobile client, the 3CX PBX must be able to contact either Apples or Google's PUSH servers on TCP port 443. Since you are allowing all Outbound traffic that shouldn't be an issue, but is the return traffic allowed? The source port used by 3CX in this case would be a random high port so there is no specific port to allow. You might want to check the firewall type and if it allows return traffic by default or not.
 
Hey @meepman

The ports required by 3CX are indeed the ones you specified. I'm just not sure about TCP 2197-2197 and TCP 5228-5230, why are those forwarded?

Also, both 443 and 5001 should not be required, only one of the two is your HTTPS port, you could check on which port you can reach the Management Console (https://abc.3cx.com:5001 or https://abc.3cx.com:443) and that would be your HTTPS port.

Regarding the issue you're facing, you should keep the following in mind:

When a call is made to a Mobile client, the 3CX PBX must be able to contact either Apples or Google's PUSH servers on TCP port 443. Since you are allowing all Outbound traffic that shouldn't be an issue, but is the return traffic allowed? The source port used by 3CX in this case would be a random high port so there is no specific port to allow. You might want to check the firewall type and if it allows return traffic by default or not.

I figured that's what the issue is, I don't have inbound ports open for the higher ports. Resolved it by allowing inbound ephemeral ports for the subnet

If anyone is wondering the fix I added an inbound rule to my network access control list to allow 32768 - 65535
 
  • Like
Reactions: ChrisC_3CX
Glad to hear you were able to resolve the issue, but do note that we recommend deploying using the method described in our guide which will automatically take care of the required firewall configuration for you: https://www.3cx.com/docs/cloud-pbx-amazon-aws/
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK