Anyone have phones successfully working Remotely?

Status
Not open for further replies.
amygoda said:
Hello Dbarney,
I told you before I used Nokia E61 connected to 3cx with out tunnel or vpn
I can make a calls like I'm in office ,recive a calls with caller id and The voice more than perfect
so it's not 3CX it's what device you'll use

I can understand that, that is why my initial question is what equipment people have experience with getting to work. The topic changed a bit when I kept hearing vpn/tunnels being used.
 
The Polycom's work just fine directly over the internet behind a home firewall. You jus have to manually configure all of the NAT information on the phone and open the necessary ports on your firewall if necessary. Polycom phones do not have STUN or ICE support so they are unable to determine the public IP of the firewall that is going through. The solution to this is to manually enter the Public IP address of your home firewall into the Polycom's NAT IP address field. This can be a real pain if your ISP changes your IP address frequently. As long as your ISP does not change your IP address frequently you should not have many problems.

I am currently using a Polycom SoundPoint IP 430 at my home with 3CX at work. Both the phone and 3CX are behind full cone NATs. The phone works fine and can place and receive calls. I use it as a toll bypass to speak with my wife during the day.

Most larger companies and VoIP providers use a Session Border Controller (SBC) that intercepts the SIP and RTP packets before they travel to the SIP server. The SBC will be able to discren the public IP address that the phone is located at and modify the SIP and RTP packets so that the invalid private IP addresses and ports are replaced with the proper public IP address and ports. Since most people using 3CX don't own a SBC or a firewall device that has a proper SIP application layer gateway, they tend to have problems getting hard phones with no STUN or ICE support working at their employees homes.

Since a hardware VPN introduces only marginal delay and jitter, an employee is usually issued a small firewall, such as a cisco ASA5505 or Pix 501 along with a hardware phone. This eliminates any problems with a home users firewall. Many companies use VPNs because they do not want their SIP and RTP packets travelling over the public internet unencrypted.

I also have a UTStarcom F3000 clam shell phone that I use at home directly over the internet. It works just fine and has stun support. The only downside is the STUN support is not SSID specific so I need to remeber to turn it on at home and off at work. I have even used the phone at the local pizza joint and at the local burger joint which both have open wifi.

SO, unless you really want to learn the ins/outs of SIP, RTP and firewall/NAT issues you should look for a hardware phone that has STUN support. This is an often requested feature of Polycom and they seem VERY reluctant to offer it. It probably has to do with them not wanting to deal with end users and only with resellers/channel/voip providers. They then shift the requirement for proper equipment/configuration onto their reseller base.
 
moon 1234

Good insight thank you. What can one do if they have a Remote PolyCom Phone? Can it be made to work?
 
I did a test today for spa3102 and grandstream 2020
oth works fine and I called both ways
 
We have a bunch of Cisco 7965s working perfectly from people's home offices. We don't use VPN because we want to minimise jitter and configuraiton hassles (we're not that bothered about encrypting the traffic between home offices and our main office). We have given the 3CX server its own public IP address at our office (in fact it has a private address but it is mapped with 1-1 NAT to a dedicated public IP address). The phones at people's home offices are usually behind a NAT, so the Cisco phone has a private IP address, but setting <natAddress>a.b.c.d</natAddress> in the Cisco phones config to the public IP address of the home DSL router and forwarding the RTP ports in the home NAT router to the private address of the Cisco phone work perfectly.

The Cisco 79x5 phones are trully awesome, and have a astonishing call quality on high latency links, especially compared to the Polycom phones we have also used. (They are just a bit of a pain to configure).
 
Was there a final conclusion on this ?

I too would like for remote softphones to connect in to the WAN address of the 3CX and be able to authenticate and make calls. I have the necessary port forwarding enabled, i.e. 5060 (TCP), 9000-9015 (UDP/TCP).

What I have discovered is that with the VPN off, the 3CX Softphone is able to successfully log in to the WAN IP Address and autneticate. Calls made to this Soft Phone extension number route fine both from the LAN where the 3CX is, and also from other clients logged in via VPN. However any calls I try to make from the 3CX Soft Phone that is not using VPN generates a message 'Forbidden' as well as the Server Status entries below.

Please can someone let me know whether a) this is achievable, and b) what configuration changes need to be made to make this happen.

Thanks in advance for any advice or guidance on this matter. Kind Regards, Lewis

22:22:02.327 Call::Terminate [CM503008]: Call(32): Call is terminated
22:22:02.327 CallCtrl::onIncomingCall [CM502001]: Source info: From: 32; To: "3CXPhone"[sip:[email protected]:5060];tag=e778ff46[sip:[email protected]:5060]
22:22:02.327 CallCtrl::onIncomingCall [CM503013]: Call(32): Incoming call rejected, caller is unknown; msg=SipReq: INVITE [email protected]:5060 tid=a04b4272523e0319 cseq=INVITE [email protected]:5070 / 2 from(wire)
22:22:02.117 evt::CheckIfAuthIsRequired::not_handled [CM500002]: Unidentified incoming call. Review INVITE and adjust source identification:
INVITE sip:[email protected]:5060 SIP/2.0
Via: SIP/2.0/UDP 192.168.80.100:5070;branch=z9hG4bK-d8754z-c025893e6739792d-1---d8754z-;rport=20132;received=82.71.0.209
Max-Forwards: 70
Contact: [sip:[email protected]:5070]
To: [sip:[email protected]:5060]
From: "3CXPhone"[sip:[email protected]:5060];tag=e778ff46
Call-ID: ZTI3ZmY0NWM2Y2RiYzg1NWIyMmZlN2FiNmQ3MjE4ZTA.
CSeq: 1 INVITE
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REGISTER, SUBSCRIBE, NOTIFY, REFER, INFO
Supported: replaces
User-Agent: 3CX Phone 7.0.3766.0
Content-Length: 0


22:22:02.107 evt::CheckIfAuthIsRequired::not_handled [CM302001]: Authorization system can not identify source of: SipReq: INVITE [email protected]:5060 tid=c025893e6739792d cseq=INVITE [email protected]:5070 / 1 from(wire)
 
I do have Grandstream 2020,2000
Linksys SPA942,962,3102,pap2t
all of them work remotely very well
I think the tip in the stun server settings
 
galal202 said:
I do have Grandstream 2020,2000
Linksys SPA942,962,3102,pap2t
all of them work remotely very well
I think the tip in the stun server settings
Thanks I'll give that a try.
 
Unfortunately that didn't make a difference on the STUN server side.

However I thought I would test in the X-Lite SIP Soft Phone and that was able to connect to the WAN address and both make and receive calls. So I wonder whether it's a limitation/bug in the 3CX soft phone or something that I do not understand. I would suspect the latter.

Alas if the X-Lite works, then that reassures me about the hardware-based SIP Phones of which I have yet to test. Ideally I would like it solved for the 3CX soft phone as it provides visibility of extensions that are available and that is key for a remote working virtual team.

So the problem remains albeit isolated to the 3CX soft phone - so any ideas greatly welcomed. Lewis
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,885
Messages
589,547
Members
164,745
Latest member
Herm77