Admin console 403 Forbidden when setting up self hosted PBX

LynxHS

Customer
Joined
May 14, 2025
Messages
3
Reaction score
0
Hi,

I am trying to setup a new self hosted 3CX PRO (20.0) phone system following the Installing 3CX using 3CX Debian ISO guide. I made it to step 5, uploaded the configuration file, and visited the local web-interface (http://<ip of machine>:5015), which displayed the link to set a password. However, following that link leads me to a 403 Forbidden error. When I access the 3CX portal --> "My Systems", the subscription is listed with a green status light and provides me with a link to the subscription's admin console, which also leads me to a 403 Forbidden error (the two links may be equal, I can't tell anymore). This was about two weeks ago and I didn't touch the PBX since until today.

The PBX runs on a VM which was shut down for the last two weeks. After restarting the VM, I was able to access (http://<ip of machine>), which prompted me to login with my 3CX account, but it did not accept my user/pw. Trying to access (http://<ip of machine>:5015) results in "connection failed".

I specifically did not configure a split DNS or the firewall yet since I consider them as potential failure points for now.


My obvious question is now: How do I proceed?

Any help is appreciated.
Thanks in advance!
 
From what I can see, you have one on-premises system installed with port 443. This port, though, points to another location and not the 3cx system IP.
 
firstly, is your <IPOfMachine> a LAN or WAN address?

If WAN, go through your firewall setup.

If LAN you should be able to go to http://lanip:5015 and then either upload your set up config or insert the URL generated when setting it up.

If youre trying to access it via the customer portal, it will use the WAN, which is likely hitting your router management port on 443 (providing you didnt change this port).

I would suggest you rerun the set up.
 
First of all, thank you very much for your quick replies!

From what I can see, you have one on-premises system installed with port 443. This port, though, points to another location and not the 3cx system IP.

Correct. However, I never specified any port nor had I the option to do so.

firstly, is your <IPOfMachine> a LAN or WAN address?
For now, I am operating in my LAN only.

I followed @Alphabetic 's advice and rerun the setup (again following the guide I linked above). I noticed that virtually all of the config parameters in steps 4.4 - 4.17 were seemingly automatically filled in by the system and there was no way for me to specifiy anything. The only thing I needed to do was to enter the config file URL. After the setup was done, I noticed three things:
  1. I actually was able to login under http://<ip of machine> using my email and the password that 3cx generated for me during the "Install"-process (note that its still not using the 5015 port). I now have local access to the admin console, which is quite nice (That I could not do this last time is thus probably due to typos).
  2. When I click the link (https:/my-company.on3cx.com) using the customer portal, I still get the 403 Error.
  3. During setup, the console displayed all kind of log messages, but the following seems relevant to me:
Enter a FREE port for HTTPS. Recommended 443 or 5001.
Port: 443
Enter a FREE port for HTTP. Recommended 80 or 5000.
Port: 80
Enter a FREE port for the SIP server. Default 5060.
Port: 5060
Enter a FREE Tunnel port. Default 5090.
Port: 5090

It seems to me that the system automatically chooses the 443 port.

My follow-up questions are now:

  1. Is this 443 port thing actually bad? Does it have any advantage/disadvantage over 5015 or 5001?
  2. Both the links http://<ip of machine> and https:/my-company.on3cx.com point to the same thing, right? Just one time using LAN and the other time using WAN. If so, it makes sense to me why I get 403 error since I did not yet setup firewall/split DNS.

Again, thank you so much!
 
The move comes as 3CX did away with the "internal/external" settings for provisioning and such so that everything is uniform.

the idea to drop the 5001 makes it easier for set up and users to access as HTTPS is 443 so one FQDN is nice and easy for everything all around.

If you want to configure your own port then when you go through the setup and get your URL/download. Open the download (XML) and modify the port to what you desire.


http://ipofmachine will point to your LAN IP.
[PC] -> [PBX] -> [FIREWALL]

http://fqdn will point to the WAN IP.
[PC] -> [FIREWALL] -> [PBX]
 
Last edited:
The move comes as 3CX did away with the "internal/external" settings for provisioning and such so that everything is uniform.

the ideal to drop the 5001 makes it easier for set up and users to access as HTTPS is 443 so one FQDN is nice and easy for everything all around.

If you want to configure your own port then when you go through the setup and get your URL/download. Open the download (XML) and modify the port to what you desire.


http://ipofmachine will point to your LAN IP.
[PC] -> [PBX] -> [FIREWALL]

http://fqdn will point to the WAN IP.
[PC] -> [FIREWALL] -> [PBX]
Alright, that makes it pretty clear.

Thank you very much!
 

Latest Posts

Forum statistics

Threads
111,962
Messages
589,996
Members
164,867
Latest member
swegner