Change port 9000

Status
Not open for further replies.
OK So I have a partial success, and a slight complaint. I've taken the test server home to see what happens on a different router and different ISP. On the Draytek 2830Vn I use I still have trouble with the SIP port but now I'm getting something like "Full cone NAT test fail", which I believe means the connection made it out unmodified, but the test from the outside in failed?

So try another router... Trying the Plusnet branded Sagemcom router I have as a spare I get "Full cone NAT test fail" initially with no forwarding configured and "done" (SUCCESS) for ALL PORTS when I've configured it.

In short the free router succeeded where the Draytek appeared to fail. Evidence says that it IS the router.

My complaint is that the "cone" terminology in NAT may make sense at enterprise level but it is really confusing when dealing with "soho" routers.
 
Last edited:
Update: Full success on the Draytek, ran into the VOIP port number issue and once that was changed it was all clear.
Next step may be to set up a 2830 router at work.

Any ideas for how to detect if it is being blocked at the ISP? It is BT FTTP.
 
OK on a "Fiddle with it till it breaks to find out why" basis I start looking around the firewall options. "Enable strict security firewall" is selected on the office router but not on my home one. I try selecting it on the home one and 5160 is immediately blocked. Deselect it and the block persists. Reboot with it deselected and it works.

Hopefully problem solved.
 
Just an FYI from another Draytek user: AFAIK the 'enable strict security firewall' blocks everything that is not active in NAT Session Table (i.e. an IPv4 connection initiated from a device within your network). So anything not matching an entry in this table is dropped (including IPv6 I believe). This is probably not what you want, so disable this! The combination of NAT Open Ports coupled with suitable firewall rules works fine for me on my 2860 (and the 3CX firewall test passes - but I have to temporarily turn off my Draytek firewall rules to allow traffic from 3CX servers into my network).
 
So do you mean the system works with the firewall enabled, but just needs it disabled to pass tests?
 
Since I have 'open ports' for 5060, 5090 & 5001 & 9000-9xxx set up in my Draytek 2860 router that forward I/C to my local 3CX machine, I have set up corresponding Draytek firewall rules to block ALL incoming port 5060 & 5001 connections EXCEPT those from my 2 VoIP trunk providers (and for 5001) my mobile phone IP range. To pass the 3CX firewall test these rules must be temporarily disabled!
 
Update for anyone interested: I reinstalled with "vanilla" port choices. My router configuration now has port forwarding set so connections from our provider's IP forward to the current PBX and other IP addresses forward to 3CX. This seems to give me both systems side-by-side, enough to carry out a simple trial run.

Now if I could just persuade someone else to install the app I could actually try making a call on it.

As the current connection is authenticate-by-IP (Gamma) I believe I ought to be able to take over the trunk temporarily just by changing the router rules.

I've tried out of hours, it works for outbound but I get silence for inbound. No error just silence.

The existing officeserv system appears to be using ports starting at 30000 for inbound. I wonder if the Gamma account is configured specially for our PBX?
 
Status
Not open for further replies.

Forum statistics

Threads
111,940
Messages
589,848
Members
164,830
Latest member
business@brightwaylogisti