403 received on SIP Refer

Status
Not open for further replies.

sam.phillips

Platinum Partner
Advanced Certified
Joined
Mar 11, 2019
Messages
185
Reaction score
135
Call flow is like this:

SIP Trunk A DDI Inbound Rule - Forward to Outside Number "7100"

Outbound rule set as "Prefix = 7, Length =4, Route = SIP Trunk B"

So call comes in on Trunk A, then caller is connected directly to trunk B, where a third-party IVR is played.

Then that IVR does an attended transfer back to 3CX over Trunk B to the "DDI" 7101. (Inbound Rule set for 7101 - Go to queue).

When the transfer is triggered, Trunk B sends a "SIP REFER" message. We expect 3CX to respond with 202 Accepted, instead it throws a 403 forbidden.

Here is a flow of the transfer happening:
1585604260535.png

And specifically the SIP refer packet info:
1585604604203.png

Any thoughts on how I can get 3CX to allow this transfer to complete successfully?

I get the same issue when "Trunk B" is set up as a bridge too, just FYI.
 
From the capture sent it covers (from what I can see) only the local members of the call flow (I assume without seeing this is 3CX and a dialling endpoint (such as a phone).

Do you have the leg of the call from the trunk itself, or is that local leg (user-agent cabcall) not an actual SIP trunk but a local connection to something 3rd party. A diagram/call flow would be handy for the sake of clarity.
 
Here is a high level diagram...
1585642078281.png

Does that make sense?

So the 4 digit 7xxx numbers are treated as outside numbers and DDI's. The 3rd party IVR operates on a sort of "pair" system. e.g. I send the call in on 7100, it sends the call back on 7101.

I just don't get why 3CX throws 403, at the transfer attempt from "Trunk B".
Edit: and sorry, to be clear, the user agent "cabcall" is a separate 3rd party PBX. It o ly interfaces to 3CX over a SIP trunk connection.
 
For SIP Trunk B, do you have in the "Options" tab options "Supports Re-Invite" and "Support Replaces" enabled?
I'd give that a shot if not.
 
Yes I have re-invites and replace enabled on both the trunks. Have also just tried toggling 'PBX Delivers Audio' just as a test, made no difference.
I've also tried with SIP URI calling enabled just in case that relaxed security slightly (even though it shouldn't be required for this situation). Made no difference.

I can supply a complete capture file of it. Just wasn't sure if I should post that in a public forum haha!
 
No ideas here?

I just can't see the reason for throwing a 403 in this scenario...
 
Hello @sam.phillips

I am pretty sure that we do not support a REFER message coming from a provider but i would like to take a look at your capture and support info.
Please send me a p.m if that would be possible
 
Thanks for the kind offer Yiannish, PM sent.
 
Status
Not open for further replies.

Forum statistics

Threads
111,941
Messages
589,856
Members
164,832
Latest member
Boblatino