Cannot log in to FQDN but can login local IP address. SSL warning on IP login not secure.

Status
Not open for further replies.

jakeboyle

Customer
Joined
Nov 18, 2013
Messages
13
Reaction score
0
After upgrading from 15 to 16 I can never log in to the management console of domain but i can log in to Mant console via the ip address. Phone system works fine.
But I get a warning that local IP is not secure and the certificate is wrong on the ip login.

If I try to log in to Management console from domain - the certificate is fine but it won't let me log in using the correct credentials - access denied too many login attempts. My IP is not in the IP blacklist. I have checked the public ip is correct and re-saved license.

How can I get the correct certificate on the local ip address. If I ping the FQDN it has the correct public IP address.
Thanks for any help
 
there are no Certs which can work on IPs, Certs need a name which they "cover".
I assume you are not in the same network as the PBX but remote to it, or in the same internal network behind the same firewall/router?
 
Hopefully you aren't making the same mistake I did! I set up a customer's system in the office and had the same problem you did. thing was our 3CX was the one the port forwards were set up for and both FQDNs came to the same public IP address, Guess which one I was actually trying to log into! It would explain why you are getting to a login banner but not getting in.




AHA. I just discovered there is a Foscam net camera on the network and my 3cx domain is trying to use the foscam security certificate !!

Not sure how to resolve that other than remove camera which i don't want to do.?
 
Last edited:
Not totally sure if I understand the issue , please answer these questions.

1. Access remote via fqdn,

If you do an nslookup on the fqdn does it point to the wan IP of your network ?

If you try to access the 3cx management console https://fqdn:port (port will be 444 or 5001 depending on your config) do you see the 3cx login screen without any errors.

Have you setup port forwarding on the router to point 3cx ports to the 3CX server https://www.3cx.com/docs/manual/firewall-router-configuration/

2. Internal access, machine on the same network as the 3CX server

Can you access the server via IP address and port (you will get ssl errors)

To access via fqdn (i.e. https://fqdn:port) have you setup spilt dns, to point the fqdn to the 3CX server internal IP address -https://www.3cx.com/docs/creating-fqdn-split-dns/ Depending on the router, you maybe able to setup an dns entry to point to the internal ip address
 
yes nslookup points to public IP.
I see management console with https: and 5001
all port forwarding is correct
can access by ip with port 5001 and errors
but i'm concerned that 3cx appears to be using my foscam ssl from my internal ip camera !
 
can access by ip with port 5001 and errors
but i'm concerned that 3cx appears to be using my foscam ssl from my internal ip camera !

You will get errors when you try to access via IP address - this is normal. You are trying to access a website that has a ssl certificate assigned to it and you are accessing the site via IP address and not fqdn

When you access the 3cx management console via FQDN, click on padlock and it will tell you the ssl being used.
 
You will get errors when you try to access via IP address - this is normal. You are trying to access a website that has a ssl certificate assigned to it and you are accessing the site via IP address and not fqdn

When you access the 3cx management console via FQDN, click on padlock and it will tell you the ssl being used.

that's what worries me - it is using my foscam ip camera SSL certificate. and that is why chrome is giving me alarming messages. I thought the FQDN from outside would see the 3cx security certificate
 
I would say this is a network / router setup issue - not 3CX

If you access it internally via fqdn or ip what ssl certificate do you see.
 
I would say this is a network / router setup issue - not 3CX

If you access it internally via fqdn or ip what ssl certificate do you see.

Using the ip address the certificate is issued to 3cx but says it is invalid, and I can login
using the FQDN internally with port 5001 the cert is issued to 3cx and IS valid - but wont let me log in
 
Check your blacklist to see if your internal IP address has been blacklisted.

Can you post a screenshot on the fqdn web page and any error messages - remove or mask the url
 
OK. Allow management console access was restricted to specific ip addresses, the moment i relax that I can log in to the FQDN - even though all the internal ip addresses are allowed it seemed to ignore them.
I changed the secure port in the router to a different port from 443.
something has fixed - probably the former - "allow access from everywhere"

This whole thing came about because i couldnt get any remote phones to work (still cant) unless i made a VPN connection between the two routers. the errors thrown were always about the FQDN. I think i've been confusing too many issues

thanks everyone for the help
 
The fix for us not being able to access the management console was to allow France and Poland through country blocking in our SonicWall.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,945
Messages
589,871
Members
164,837
Latest member
Support99