3CX UDP Ports

Status
Not open for further replies.

Scot Busby

Customer
Joined
Jun 8, 2017
Messages
87
Reaction score
19
This is likely a very silly question, however, when setting up 3CX, the Media server ports to allow through the firewall are listed as being 9000-10999. My question is - do we need to have all these ports open/exposed to the internet or can we pair down these ports based on the maximum number of simultaneous calls for which we are licensed?

In other words, if the system is licensed for only 16 simultaneous calls, can we randomly choose to only open up 32 ports in the range of 9000-10999 rather than the entire 1,999?

My apologies for the stupid question, but could not find clarity anywhere.

Thank you!
 
Going by the audio complaints, a while back, after the port range was expanded, I'm going to "guess" that the port numbers used, increment, as time goes on. The reason I assume that, is because restarting 3CX usually ended up clearing the issue, for a while. Someone would have to confirm this.

This.. https://www.3cx.com/docs/ports/ doesn't really give you any options about using a particular number of those ports.
 
Thanks @leejor for the comments.

It's interesting to note that during our configuration and testing phases of the 3CX installation, I actually reduced the number of ports as I described above. I picked about 40 ports in the 9000-10999 range and only opened those up on the firewall. We've been using the system like this for about 1,600 calls spread over about 1 month and have not had any issues. I think we might have restarted the server once during this month, but those were for unrelated OS updates.
 
Not really sure what limiting the ports actually accomplishes from a security standpoint. At the end of the day the only thing that should be using those ports is the 3CX Media Engine so if there's a vulnerability there it's going to be exploited regardless of the number of ports you have open. If you are really paranoid you could simply restrict access to that range to your provider and keep remove devices on tunnel/VPN but I think restricting the actual range is just asking for problems.
 
Thanks @cobaltit for the comments.

I do have restrictions for our SIP provider associated with the appropriate open ports, so should be covered there. Right or wrong, I guess I was just figured the fewer ports exposed (less surface area) the better and the system seems to work using this method. Having said that, your point is taken and I don't want to cause any unforeseen anomalies by restricting ports which should be open.
 
Hello @Scot Busby

Please note that you should not restrict any UDP ports on the firewall as the media server will increment the ports for each call. The fact that your system is working tells me that your firewall handles traffic well and allows audio to go through all audio ports. However you should open all ports for the moment the firewall does not manage to handle these ports well to avoid any audio issues.
To add to what @cobaltit mentioned regarding security, the 3CX media server will drop any packets that are coming to a non negotiated port.
 
Status
Not open for further replies.

Forum statistics

Threads
111,910
Messages
589,690
Members
164,775
Latest member
Chester McTester