3cx mobile app stuck on 'connecting' - firewall checker now failing when it used to pass?

Status
Not open for further replies.

Serco

Forum User
Joined
Mar 15, 2019
Messages
37
Reaction score
5
Good evening all

Since the outbreak of corona, our office like most has started working from home (no surprises!). A few people asked me about using the 3cx mobile app, so we have been investigating it internally. When connected to the internal wireless network in the local office, it connects and works after scanning the QR code = great!. However, once outside of the network it gets stuck on 'connecting' and doesn't work.

I have been looking at this this evening at home and read a support ticket suggesting checking the firewall checker. In the dashboard, it showed a green tick as i had got it working when we had gone live with it around 9 months ago. I decided to run it again and this time it failed properly starting with SIP server - then 5060 and 5090 and then all ports from 9000 onwards............in other words a massive fail!

I checked with a colleague if calls could be made in and out of the system and they can, so this failure is not affecting basic phonecalls from what i can see luckily. However, i imagine all these failures probably do point out why my 3cx mobile app cannot work outside the network.

I have sonicwall 3600 HA pair in place and initially set up the 3cx using the 3cx configuration guide for sonicwall - this did get the green tick showing on the firewall checker - but i remembered that after this we edited the rule and NAT policy for sources to be only our phone providers IP range. We thought this would be good practice to keep the rule locked down instead of using the 'any' option

Does this sound like the reason why the firewall checker would fail - due to our lockdown on the source field in the firewall rule / NATTING?
Is it likely that i would need to contact our phone provider (Andrews & Arnold) to seek advice for what ports they use for SIP in case it is not 5060?
Am I being too cautious trying to lockdown the firewall rule to our individual provider (just trying to be security conscious :)

I appreciate any advice or knowledge some of you may have on this matter
Thanks in advance
Andy
 
If you are blocking all but certain IPs (your providers), then that is definitely going to be a problem. If all outside phones are using the 3CX App, which usually means using the tunnel, then port 5090 will have to be open.
 
3CX won't help troubleshoot if the firewall checker doesn't pass, but in this case, as @leejor mentions all you need for the mobile client to work is 5090 (TCP/UDP) and 443/5001 (TCP, depending on what port you chose for the web port). You can continue to restrict 5060 to your provider. That being said it wouldn't hurt to go back to the original configuration and then run the checker to make sure that is the only issue.
 
Thanks Leejor / Cobaltit - thought this could be the issue. We had seen some attempts by people trying to hack into our 3cx as we had left it as 'any' in the source, so we secured it to only be accessible by our providers ip range. That stopped the hacking attempts I'm pleased to say

The rule for the restricted ip's includes the complete list given in the 3cx config for sonicwall so they are all allowed including 5090 and 5001. Would i need to obtain individual mobile users ip addresses to be able to get them to work and add them to the source list? Seems like thats gong to be difficult to achieve given ip's probably change for mobile connections all the time?

I must be doing something wrong here? The original sonciwall config seemed to be wide open.
I will try reverting to the original NAT & access rule and recheck the firewall check out of hours, but i don't want to leave our system vulnerable....
 
Enable the Global Blacklist feature that came with 3CX V16. It will protect you from the most well known attackers.
 
Thanks John - where do i find that please?
 
Settings > Security > Anti-Hacking tab
1584613671650.png
 
Brilliant - thanks I'll give that a bash
Thanks all for your replies as always
 
  • Like
Reactions: JohnS_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,940
Messages
589,845
Members
164,829
Latest member
Schnittker