3CX Tunnel Protocol Port 5091 ?

Status
Not open for further replies.

COM-TEL

Bronze Partner
Basic Certified
Joined
May 14, 2017
Messages
71
Reaction score
4
My customer has a cloud based version of 3CX and uses an SBC to negotiate calls.

The SBC uses port 5090 and port forwarding has been done on the router and everything works well.

The customer now wants an additional instance of 3CX but installed on premise. This has been installed and all the firewall tests are successful except the 3CX tunnel protocol.

As the customer already has an SBC using port 5090, I have created the new on premise instance using port 5091 as the Tunnel Protocol ( and done the port forwarding) but this has failed the Firewall check.

Surely I cant have the cloud based instance (SBC) and the on premise instance both using port 5090 for the tunnel protocol?

Kind regards.
 
You do not have to setup port forwarding on the router protecting the sbc - all traffic is outbound. - remove this setup

Change the on premises tunnel port back to 5080 - adjust the firewall and run the firewall tests.

How many wan ip’s Does the customer have ?- I.e more than one
 
Normally, SBCs, are located outside the local LAN, so one port will work with any number of them as they are identified by their public IP + port. I'm not sure why you would have a need to use an SBC on the same LAN as the 3CX server, but I can't see why it can't use the same port as the external SBC(s). There may however be an unforeseen issue, as you are using it in a manner not intended.
 
Saqqara
Thank you for your reply

Customer has one static IP.

Can I change the router configuration to port forward 5090 to 5091 as it wont let me change the port on 3CX.

Leejor
Thank you for your reply

The SBC is used to contact the cloud based instance and totally separate to the newly installed on premise version. Two totally dfifferent instances and different DDI's / Telephones etc. It was originally put in to overcome the hideous virgin media firewall.
 
If the local SBC is connected to another instance, then it can't be assigned a local port number that conflicts with the local 3CX install (5060), the fact that the local 3CX "looks for" tunnel traffic on port 5080 should not affect the local SBC contacting the remote 3CX on 5080.
 
If the local SBC is connected to another instance, then it can't be assigned a local port number that conflicts with the local 3CX install (5060), the fact that the local 3CX "looks for" tunnel traffic on port 5080 should not affect the local SBC contacting the remote 3CX on 5080.

Thanks Leejor
They are on separate machines.
I didnt appreciate the "in" and "out" tunnel traffic.

I have removed the 5090 port forwarding to the SBC but Im still getting the firewall error on 5091.

Does 3CX recognise 5091 even though I have stipulated it in the install configuration do you know?
 
Personally, I have not changed the ports from the defaults, so I can't answer that. Someone else probably can.
 
@COM-TEL

Assuming you have installed a 3CX on Debian OS using 3CX ISO then after you have make changes during installation, the IPTABLES have to be modified manually afterwards.
The IPTABLES contain the default ports, not the modified ports.
 
Hi @complex1

Its on a windows server. (first time use, I usually use the iso)

I have just done a fresh install as its not possible to change the port numbers once the PBX has been created, apparently and the issue has now been resolved.

Clearly the issue was with port 5091. Now reset to default and everything is working.

Thank you everyone for your assistance.
 
Since you delete 5091 port forwarding on your firewall, did you reboot it ?
5091 firewall rule is gone but surely is always running live until a reboot wipe it
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,932
Messages
589,806
Members
164,805
Latest member
Diana Paladutsa