3CX v20 – One inbound DID rejected with 403 “Caller is not identified” (other DIDs on same trunk work)

Univ. of North Florida

Premier Customer
Basic Certified
Joined
Nov 6, 2020
Messages
38
Reaction score
7
Hi all,


Could you please help us with this issue? I’m running 3CX v20 with an IP-based SIP trunk (UDP/5060). Incoming/outgoing calls work fine for the main trunk number and most DIDs, but one specific DID is being rejected.

Issue​

Inbound calls to 904******* consistently fail:
  • 3CX sends 100 Trying
  • then replies 403 Forbidden
  • with header: Warning: 499 “Caller is not identified”
  • call shows as rejected in SIP flow/call attempts

At nearly the same time, calls to other DIDs on the same setup/trunk complete normally, so this looks DID-specific rather than a general trunk outage.

What I’ve verified/tried
  • The DID 904******* exists in only one SIP Trunk in 3CX (no duplicate DID entries anywhere else).
  • There is a second SIP trunk configured in 3CX, but it is not used for this DID. To eliminate overlap, I removed all DIDs from that trunk and disabled both inbound and outbound calls on it.
  • I reviewed Inbound Rules to confirm there are no other rules/patterns that could be matching or intercepting 904*******.
  • Other DIDs on the system are working for both inbound and outbound calling; only 904******* is rejected with 403 Forbidden / Warning: 499 “Caller is not identified.

My question is: given that other DIDs work, what could cause only one DID to return a 403 /499 “Caller is not identified”?
 
Last edited:
Regarding your question, please verify that the DID configured on the trunk is being received from the provider in the same format and not in E.164 format (e.g. +1234567890).

Additionally, if the number included in your message is a real DID, we recommend editing your reply and removing it for security and privacy reasons.

Kind regards,
 
Regarding your question, please verify that the DID configured on the trunk is being received from the provider in the same format and not in E.164 format (e.g. +1234567890).

Additionally, if the number included in your message is a real DID, we recommend editing your reply and removing it for security and privacy reasons.

Kind regards,
Thanks for the suggestion.


I verified the DID format being delivered from the provider: the INVITE is received in 10-digit format (e.g., 904*******), not in E.164 (no leading +1). I’ve also double-checked that the DID is configured on the 3CX trunk in the same format.
 
So, to verify that this is a direct call to the DID and not a call diverted by another number being dialled?
 
So, to verify that this is a direct call to the DID and not a call diverted by another number being dialled?
Yes, confirmed. This is a direct inbound call to that DID (the caller is dialing the DID itself), not a diverted/forwarded call from another number.
 
Is it rejected regardless of by whom and where it's called from?
 
  • Like
Reactions: YiannisH_3CX
Assuming this DID is configured exactly the same way as every other inbound rule, and it is pointing to a functional endpoint, then you might consider deleting the DID, and then configure it again. Maybe something didn't quite work the first time? I've seen that before where objects inside 3CX stop working or never work as expected, and deleting and recreating fixes the issue. It is a long-shot, but something that is easy/fast to try.
 
Is it rejected regardless of by whom and where it's called from?
3cx is rejecting the call with the message "duplicate DID". The call is coming from an external number.
 
Assuming this DID is configured exactly the same way as every other inbound rule, and it is pointing to a functional endpoint, then you might consider deleting the DID, and then configure it again. Maybe something didn't quite work the first time? I've seen that before where objects inside 3CX stop working or never work as expected, and deleting and recreating fixes the issue. It is a long-shot, but something that is easy/fast to try.
Thank you for your response. Yes, this DID is configured the same way as our other inbound rules, and it is assigned to a valid/working user/endpoint. I also tried rebuilding it to rule out a corrupted object:
  • Removed the DID from the SIP trunk and added it back
  • Removed/recreated the user/extension and reassigned the DID
  • Assigned the DID to a different user/extension
Unfortunately, the behavior did not change, inbound calls to this DID still receive 403 Forbidden with Warning: 499 “Caller is not identified.”
 
In this case, it's best to get this checked. If you work with a partner, you can contact them to initiate the troubleshooting for you. Alternatively, if you manage this system yourself, you can open a support ticket by purchasing one directly through the admin console.
 
Hang on, you said the error says "duplicate DID". A DID must come from only one carrier. Do you have the same DID assigned to more than one carrier (trunk)?
 
The easiest way to check if you have a duplicate DID is to take that DID and go to assign it to an extension.
Just type the DID in the Assigned DID number(s) field and see if it comes up twice.
 
In this case, it's best to get this checked. If you work with a partner, you can contact them to initiate the troubleshooting for you. Alternatively, if you manage this system yourself, you can open a support ticket by purchasing one directly through the admin console.
I will open a ticket. thank you for your help.
 
Last edited:
Hang on, you said the error says "duplicate DID". A DID must come from only one carrier. Do you have the same DID assigned to more than one carrier (trunk)?
No, the DID is only assigned to one trunk. When I assign the DID to a user, it appears only once in the list. If the same DID existed on two different trunks, 3CX would show it twice, and I’d be able to select it from either trunk. That’s not the case here.
 
The easiest way to check if you have a duplicate DID is to take that DID and go to assign it to an extension.
Just type the DID in the Assigned DID number(s) field and see if it comes up twice.
No, sir, it only comes up once. I checked by entering the DID in the Assigned DID number(s) field, and it appears only once. That’s why I’m confused about why I’m still getting the 403 Forbidden error. Thank you; you have always been helpful to us.
 
Last edited:
At this point you should create a ticket so our support can have a closer look.
 
At this point you should create a ticket so our support can have a closer look.
Yes, I think the support needs to take a look. Thank you for your help.
 

Latest Posts

Members Online Now

Forum statistics

Threads
111,831
Messages
589,276
Members
164,660
Latest member
RJenkinsROCK