Change of Windows PBX IP broke system

Status
Not open for further replies.

IraComputing

Forum User
Joined
Jul 16, 2019
Messages
5
Reaction score
0
We updated site firewall and IP subnets. Changed IP address of PBX server and phones. Phones will connect to server and can dial out but with no audio. 3CX firewall check fails at testing 3CX SIP Server: testing port 5060 and everything after. If I switch PBX server back to original IP and it passes. Does the certificate key to the local IP? I inherited this system, and I am looking through the training and setup info.

Any help would be great.

Thanks.
 
Do extension to extension calls work? I'm guessing the firewall/port forwarding rules weren't updated to reflect the new IP address
 
extension to extension works. Updated firewall between tests to reflect correct PBX IP correct firewall, even tested with firewall open and still fails 1st failure is "testing port 5060... unmatched mapping (18110)". Switched from old netgear firewall to new Sonicwall both work with PBX on old IP 10.0.0.101 but not when using new IP 10.0.2.200. switched IP config to reflect new IP on both firewalls with no success.
 
Is this a windows install , or Debian install


i Would do a full backup, move backup file to another location.

Uninstall 3cx, reboot system

Reinstall 3cx, using the backup above - this will reset all the ip addreses
 
Thanks Cobaltit and Saqqara, this is a windows install V15.0.60903.0 on Windows 7 Pro. Looks like it is far out of date, can I updated to V16 latest? Would I be better off using the 3CX ISO and going to debian, and would the backups transfer platforms?

Thanks again,
Paxton
 
First of all you should update to 15.5 sp6 - https://www.3cx.com/blog/news/pbx-upgrade-update-6/

Would you be better off going to Debian - all depends if you know debian and how to manage it using commands

Yes - backups are transferable between windows and debian
 
Hi Paxton,

Note that Windows 7 is no longer supported https://www.3cx.com/docs/manual/

Best to choose Debian, Windows 10, or Windows Server for the next installation.
 
As you have W7 PC, if it's not a very old pc, then reinstall it with W10 x64 if you want to stay µsoft user or use iso Debian and forget windows.

If you stay on µsoft side you can upgrade for free from W7 to W10 using same key licence after w10 install. if you need some details ask.
 
I suspect this is actually a NAT rule issue, likely there is a extra rule in there that needs updated that was missed, or is buried in there. What firewall is in use and i might be able to tell you where to hunt for it at?

EDIT, just noticed you said sonicwall, what is the state of consistent nat on this firewall, enabled or disabled? and SIP ALG, make sure it is off. Also, did you create the rules manually, or did you use the server wizard in the sonicwall?
 
Thanks for the responses.
JohnS - Yes, that was one of my concerns, that makes me lean to Debian.

Aws2p - It is a POS. :) Win7Pro 64bit, Intel E2180, 2gb ram, 250gb HD. I feel like only thing worthwhile is the OS.

BrenttG - I will triple check the Sonicwall, it is setup according to the 3cx configuration notes for Sonicwall, and I find it strange that with the new and old firewall with the old Local IP it passes Firewall Checker test but when changing Local IP on system and pointing rules to new IP it fails all tests. But firewall shows no blocked traffic.
 
not seeing blocked traffic means nothing.

When you see unmatched mappings, the issue is full cone nat/static port. Or sometimes sip alg.

99% chance there are extra rules you are not seeing, or not attributing to the 3cx server that need to be adjusted to match up again. The ports are getting remapped to dynamic ports by the NAT engine, this is causing those failures, must use a rule to force static port mappings or else in the settings somewhere enable it. Depending on the firewall.
 
  • Like
Reactions: JohnS_3CX
not seeing blocked traffic means nothing.

When you see unmatched mappings, the issue is full cone nat/static port. Or sometimes sip alg.

99% chance there are extra rules you are not seeing, or not attributing to the 3cx server that need to be adjusted to match up again. The ports are getting remapped to dynamic ports by the NAT engine, this is causing those failures, must use a rule to force static port mappings or else in the settings somewhere enable it. Depending on the firewall.

Thanks, I will check on the dynamic ports, I looked back on other saved testes and that was not the original message
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,932
Messages
589,805
Members
164,804
Latest member
fcentral