3cx On Premise Firewall NAT Port

Status
Not open for further replies.

Alle CTEC

Silver Partner
Joined
Sep 11, 2023
Messages
360
Reaction score
45
I would like some guidance on the necessary ports to open on the firewall in this guide https://www.3cx.com/docs/manual/firewall-router-configuration/

It's indicated

From sip provider:

5060 TCP & UDP
5061 TCP
9000-10999 UDP

But if I don't open the UDP files from 9000 to 10999 to any, the audio cannot be heard


To use Click2Talk to call fqdn the 3cx https port and 5001, however, I had to create a rule for the caller that can go out on TCP 5001.
With the new installations will everything run on the 443?


Here too I needed the udp ports from 9000-10999?
 
Hi @Alle CTEC if you plan to use an external voip provider then you must create a NAT rule for SIP Port by default 5060 TCP/UDP and the external RTP audio ports that are in the range 9000-10999UDP.

If you are using external applications such as PWA/Web Client and Desktop App, these will use the HTTPS port by default 5001 TCP unless you have changed during the installation process and the range 10500-10999 UDP which are already in the range 9000-10999 UDP.

For mobile apps you will need to create also a NAT rule for Tunnel Port 5090 TCP/UDP and HTTPS port.

All these are the external PBX ports.

Then run the firewall checker to validate that your configuration is correct in the firewall in front of the 3CX.
 
This is not indicated in the guide!!!
It is indicated to open 9000-10999UDP from Voip Provider which is not Any. And in the WebRtc App section, ports 10500-10999 are not mentioned. Furthermore, it is not mentioned that the caller must have opened the 5001 tcp in order to use WebRtc


Request?

Do new installations use 443 to avoid the caller having to open the outgoing 5001? Thank you
 
Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet