3CX On Premise Pi 4 - FQDN or Public IP not working

Status
Not open for further replies.

Drohps

Forum User
Joined
Oct 24, 2020
Messages
21
Reaction score
1
Hello Everyone,

I have just set up 3CX on a Raspberry Pi 4 a few days ago but I am having some problems.
Version Number 16.0.930

Firstly I cannot access the management console outside of my network. I have opened all the required ports and checked that they are open. This is the case both for FQDN and Public IP (Static). With or without port 5001 at the end.
I have checked and the IP behind the FQDN is correct.
I have deleted and re-installed 3CX from scratch and received a new certificate too.
SIP ALG Disabled too on the Edgerouter.
I think I have read every post I can find regarding FQDN not resolving but haven't managed to sort it so any help with be much appreciated.

In addition to the above, but most probably related, iOS clients do not receive notifications. When within the network or from Wifi, 3CX App clients can make calls but cannot receive calls - status changes to "In a call" when ringing nothing comes through to iOS. When in a different WiFi, then iOS app not connecting at all. I am mentioning this in case it helps.

Thank you in advance and I hope the information I have provided is sufficient.
 
It's good that they work, but the rest of those services are not related in any way with iOS PUSH so they are effectively irrelevant to the issue.

I still think you should look into what I said above, repeat the iOS test but run captures both on the PBX and the Firewall WAN interface this time.

If you don't run a capture on the firewall WAN, there is no way of truly knowing whether the message from the PBX even left the network or reached the Apple APN server.

Hello John,
I have done what you suggested but to be honest I did not manage to understand much from the capture taken from the Edgerouter.

However a detail I missed mentioning so far was that missed calls do appear in the iOS app after calling. And from a different thread that I read on the 3cx forum I understand that this means the push service is actually working?

Additionally do you have any idea why mobile clients appear as connected when on 3G but when connecting from wifi, it does not always connect? Wifi's are not corporate wifi networks with firewall but home wifi networks.
 
Hello,

It really depends, I would have to see a capture made from the router WAN interface to be able to to comment with regards to iOS PUSH calls.

As for the remote WiFi, again it depends on a number of reasons, you would have to know the public IP that the WiFi terminates to, and then look at your firewall to see if there is incoming traffic from that IP, destined for your tunnel port (usually 5090). Looking at the edge router/firewall is pretty much the only way you can pin down these things.
 
Hello,

It really depends, I would have to see a capture made from the router WAN interface to be able to to comment with regards to iOS PUSH calls.

As for the remote WiFi, again it depends on a number of reasons, you would have to know the public IP that the WiFi terminates to, and then look at your firewall to see if there is incoming traffic from that IP, destined for your tunnel port (usually 5090). Looking at the edge router/firewall is pretty much the only way you can pin down these things.

Hello John,
Thank you again for your reply.
I have taken the time to do a clean installation of the PBX and the Router / Firewall to ensure there are no bugs in the router that cause this. However the problems persist.
- No push to iOS
- No presence / connection from external Wifi - presence / connection from 3G/4G is working.

I have setup VPN and this has helped making the Mac App to connect from remote wifi, however it from iOS VPN has not solved the Push Problem.

Lastly I have spoken to my ISP, and they advised that the only ports they reserve for their use are 5060, 8084, 8083, 7547 and 5800.

The only common port I see is 5060. Could this be our problem? Should I do a clean set up of the PBX again changing this port?

EDIT: some extra information if it helps - I have my ISP's Modem/Router which is in bridge mode and I only use it to connect the BRI line from my ISPs Router to my Beronet Gateway and thus they use port 5060 for their VOIP services.
 
Last edited:
Hi,

The thing is, we never actually checked the firewall captures VS the PBX captures, so the clean installation may have been avoided (although not a bad idea).

For 5060: if you only use beronet, and you have no remote trunks/STUN phones, then 5060 should not be a problem. You can keep it as is, but it will fail the firewall checker which is expected in this case.

The VPN will not solve the PUSH problem, because PUSH does not travel via VPN. I still think we need to compare captures as mentioned above, I didn't see evidence that the PUSH message ever left the firewall successfully.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,990
Messages
590,164
Members
164,927
Latest member
tohoken1