3CX On Premise Pi 4 - FQDN or Public IP not working

Status
Not open for further replies.

Drohps

Forum User
Joined
Oct 24, 2020
Messages
21
Reaction score
1
Hello Everyone,

I have just set up 3CX on a Raspberry Pi 4 a few days ago but I am having some problems.
Version Number 16.0.930

Firstly I cannot access the management console outside of my network. I have opened all the required ports and checked that they are open. This is the case both for FQDN and Public IP (Static). With or without port 5001 at the end.
I have checked and the IP behind the FQDN is correct.
I have deleted and re-installed 3CX from scratch and received a new certificate too.
SIP ALG Disabled too on the Edgerouter.
I think I have read every post I can find regarding FQDN not resolving but haven't managed to sort it so any help with be much appreciated.

In addition to the above, but most probably related, iOS clients do not receive notifications. When within the network or from Wifi, 3CX App clients can make calls but cannot receive calls - status changes to "In a call" when ringing nothing comes through to iOS. When in a different WiFi, then iOS app not connecting at all. I am mentioning this in case it helps.

Thank you in advance and I hope the information I have provided is sufficient.
 
Can you access the management console internally via IP ?

Within the 3CX management console, under settings -> network does the static public ip match your correct wan IP address.

Are the settings for the network card correct - https://www.3cx.com/docs/installing-pbx-raspberry-pi/ - Step 4 for your network environment ?

If it does, then I would say you have a firewall issue

Can you see anything in the logs of the firewall for incoming port 5001
 
Hello Saqqaea. Thank you for your prompt reply.

Yes I can access internally via LAN IP of the Pi.
Yes the Static Public IP is correct inside the 3CX Management Console
 
When you perform a firewall test, does it pass?
 
Hello Kieferschild,

Yes it does pass the firewall test.
 
In that case, where are you trying to access the external from? Did you enable admin console restriction under settings > security > security settings > console restrictions
 
I have tried for a couple of remote locations and my mobile phone as well.

Console Restrictions under Security Settings is set to "Allow Access from Everywhere"
 
So I think I have made some progress.

When within our network:
  1. I can access the management page through public-ip:5001
  2. I can access the management page through xyz.3cx.xx:5001
  3. I cannot access the management page through xyz.3cx.xx

When outside our network:

  1. https://public-ip:5001 - doesn't fail, but doesn't load either. Loads forever.
  2. xyz.3cx.xx:5001 - doesn't fail, but doesn't load either. Loads forever.
  3. xyz.3cx.xx - fails - can't connect to server.
Not sure if this helps.
 
Are you sure you have setup port forwarding correctly for port 5001

Can you see any traffic hitting your firewall on port 5001 , you may have to switch on logging.

You are using a supported web browser - Chrome , Edge (Chromium) ) or FireFox
 
I believe I have set it up correctly. Yes traffic is hitting the port from rule stats.
I was using safari but have just tried to use chrome. Same thing with chrome too.
 
Hello Saqqara. Thank you for taking the time to look into this. I have followed these steps and it is exactly what I had done. So ports have been forwarded correctly. Is there any chance that the problem is with the FQDN setup from 3CX?
 
Hello Saqqara. Thank you for taking the time to look into this. I have followed these steps and it is exactly what I had done. So ports have been forwarded correctly. Is there any chance that the problem is with the FQDN setup from 3CX?

if you can ping the FQDN and its returns your WAN then no.

Are you on a mobile broadband internet by any chance?
 
No and I have tried from 3 different broadband connections.

Shouldn't the iOS clients work normally when inside the network at least?
 
It all sounds network related.

the problems you are having are with inbound connections. Are you able to change your router or try 3CX in a DMZ?

You already know that 5001 is open as you can access it locally. I would try that firewall check again.

From outside of the network are you able to do this in CMD

telnet FQDN 5001

you should get this back

1603806072455.png
 
Last edited:
Terminal from the Mac returns:

Escape character is '^]'.
Connection closed by foreign host.


However when I run telnet with the public IP not the FQDN, I saw a domain which is unrelated to me and belongs to a different company. Not sure if there is a mixup but I have asked our ISP to provide us with a new public IP. As soon as I get it I will test and come back to feedback.

Thank you for your help so far.
 
  • Like
Reactions: AWS2P
Hello again! So i have now been allocated a new public static IP address. I have updated the management console and:

When outside our network:

  1. https://public-ip:5001 - Loads to management console
  2. xyz.3cx.xx:5001 - Loads to management console
  3. xyz.3cx.xx - fails - can't connect to server.
iOS push still not working.

Any suggestions would be much appreciated once again.

Thank you.
 
Hello again! So i have now been allocated a new public static IP address. I have updated the management console and:

When outside our network:

  1. https://public-ip:5001 - Loads to management console
  2. xyz.3cx.xx:5001 - Loads to management console
  3. xyz.3cx.xx - fails - can't connect to server.
So what you are saying everything is working as expected? The non-SSL port is not supposed to work from the outside. If you have that forwarded for some reason, you shouldn't.

https://www.3cx.com/docs/ports/
https://www.3cx.com/docs/manual/firewall-router-configuration/

For push not working, that could be a number of reasons. Does the extension have push enabled? Do you have any outbound blocking enabled? Is the firewall checker passing now?
 
Hello cobaltit,

Thank you for your response. Shouldn't I be able to remotely access the management platform from my FQDN without the port number?

I have checked again and all the correct ports are open.

With regards to push, yes it is enabled both on devices and within the extension profiles. No outbound blocking enabled. Firewall checker is passing. The error I am getting for that is

Failed to send APNS PUSH to device iPhone10,6 XYZ. Internal exception occured: The SSL connection could not be established, see inner exception.
 
MGMT console is accessible on 5001 (default port/or port you configured during install) only.

Did push problem occur prior to you upgrading to the alpha release?

You've not messed around trying to install certificates have you?
 
Status
Not open for further replies.

Forum statistics

Threads
111,990
Messages
590,165
Members
164,929
Latest member
Cloudstar