3cx on AWS Issues

Status
Not open for further replies.

dpjax

Joined
Jun 15, 2018
Messages
8
Reaction score
0
I tried the pbxexpress method and it failed saying I didn't have enough instances available. I checked my AWS account and this just isn't the case. Since that failed, I went ahead and ran a linux instance from the debian stretch page as specificied. I then downloaded and setup 3cx on the linux instance.

I've got 3cx running but I'm having trouble passing the firewall test. I have read the page for that test and it just doesn't offer me anything.

Current symptoms:

If I open the security group on the instance to all traffic any source, the test works.
If I go back to my security group that only allows traffic from my office and twilio (my SIP provider), it fails.

Current rules:

5060 UDP/TCP to US Twilio SIP addresses
9000-20000 UDP to Twilio media servers (overly large range but I found some differing ports when searching)
All traffic to my office. I am able to SSH into the box.

Obviously, something is missing from my security group...but what? What is needed to be permitted to allow the check to pass? Is it not listed somewhere?
 
I would take a look at some of the online guides:
https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-network-security.html

If these rules are specific to/from a specific IP address then if you (as a test) open up the rule to "any" does this work then - obviously this would not remain this way but may give you an indication of what the issue might be.

I am not familiar with your trunking providers method of connection, are Twilio registration based or IP authenticated SIP trunks ?
 
As I mentioned in the original post, if I open the security group wide open to any any the firewall check passes.

I am not yet to the point of troubleshooting Twilio but I do have all their required ports/IPs allowed in my restrictive security group.

What I need to know is what the other endpoint is for the firewall test. Does anyone know that?
 
Looking at the security group from a default AWS install:

Inbound
TCP 5060
TCP 5001
TCP 443
TCP 5090
TCP 5061
UDP 5060
UDP 5090
UDP 9000-9500
TCP 22
TCP 5015

Outbound:
All traffic on all ports.

Hope this helps.
 
Thanks for posting...

From your example of ports...are these open to everyone? I was hoping to tighten down the system to just the office since I have no mobile users.
 
No worries. Yes, they are open to everybody. What specific errors were you getting from the firewall checker? Why not run the checker with everything open, let it pass, and then secure everything back up and only open up if you have issues?

Also, have you seen this?

https://www.3cx.com/docs/troubleshooting-firewall-checker/
 
You also did not answer my question about IP or Registration based SIP trunks.

If IP authenticated all you need to do is have a rule which opens up "any" from the provide themselves (they do the same at their end also). If Registration based you have to set it up for individual ports.

In answer to your endpoint question, all the FW checker does is check your local firewall on the PBX side, in this case it is checking AWS, in an on premise setup it would be whatever brand you have onsite.
 
I ended up opening up the security group, running the firewall checked, then locking it back up. At least its green now.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,885
Messages
589,547
Members
164,745
Latest member
Herm77