Blacklisted 3CX IP, phones deleted?

Status
Not open for further replies.

ArtR

Customer
Basic Certified
Joined
Sep 13, 2018
Messages
48
Reaction score
5
Hi All,
Changed some settings last week to use the external FQDN in preparation of setting up and testing a failover install.
Come monday, I see our WAN IP has been blacklisted, assuming one of our clients/phones is miss configured to cause this.
Ok, got in and deleted the blacklisting and whitelisted the IP for future so we don't get blocked again.

But noticed all the handsets have disappeared from the Phones menu. They are still listed with the individuals extension settings, but these don't seem to apply or work anymore anyway.

I have just deleted and added my phone back in for now to test this but then noticed the autoprovision URL uses port 5000, which isn't forwarded on my firewall, only 5001 is as per the firewall config guide. Why would the system be trying port 5000?

So curious to know if its expected behaviour for the phones to delete off the system, or was it my config changed that caused this. And then, just why port 5000 is being used for autoprovision.. this would have worked when using LAN IP initially but failing now that it is trying via WAN IP.


v15.5.0 on windows
 
I suspect that it is the result of the changes you made and the fact that until re-provisioned, the sets would have continued to use the settings that they had. Not certain why your WAN IP would have been blacklisted, as I assume it is the public IP that the 3CX server is located at. Blacklisting would require something to make unsuccessful attempts from that IP. You might want to go back through the Activity Logs, around the date/time of the blacklisting, to see if there is anything that may clarify the reason behind that.

The sets would be using port 5000 if their current provisioning instructed them to.
 
Ok, looking at the failover instructions, I can see part of the port issue, when you select LAN, even with FQDN it will use port 5000, which isn't forwarded via firewall, so that fails that.
I guess I could resolve this with split DNS but that then breaks the 3CX DNS updating the WAN IP as needed during an outage.

For my phone, i can see a bunch of registered/unregistered entries which has a remove contact entry, but can't see anything about removing phone.

Testing further i guess.
 
As per links posted by leejor, you need to configure spilt dns so that the fqdn points to the internal ip addresss of the 3cx server for local devices.

In the event of a failure, 3CX will update the wan IP address, but you will have to manually update the internal dns settings for the fqdn.

https://www.3cx.com/docs/failover/
 
Hello @ArtR

Since the phones are configured as local LAN then port 5000 (http) will be used as the server assumes the phones are local. By since you switched your phones to the FQDN without a local DNS entry then when the phones perform a lookup on that FQDN they will get the public IP of the phone system. So the phones will try to connect to the WAN IP but with port 5000 with nginx does not allow.
That will cause your phones to be blacklisted and become unregistered. Once unregistered they will not show up under the phones tab. You need to create a DNS entry for your local network to point the phones to the local IP of the PBX.
 
Thanks for the info, I had assumed the failover setup specifically shouldn't use a split DNS so it could failover without much input as long as both servers were setup right public IPs etc.

Will get the split DNS setup it seems.
 
Status
Not open for further replies.

Forum statistics

Threads
111,909
Messages
589,685
Members
164,773
Latest member
ccocala.org