Solved Connecting to 3CX in AWS from softphone

Status
Not open for further replies.

dpgator33

Free User
Joined
Mar 1, 2019
Messages
10
Reaction score
1
I've provisioned a 3CX server in AWS (3CX provided image and also all networking rules applied) but can't seem to get my softphones (no hardware phones at this point) to connect. So far I'm only using IOS. Account settings on the softphone look correct, I've even tried adding a new extension and running through the account setup on the phone all over again. I did the QR code method, but that hasn't worked. I know also that the DNS isn't right, so I change the connection settings on the phone to point to IP address. Given that the firewall (security groups in AWS) are set by 3CX in the image template in the provisioning part, I'm really kind of stumped that this isn't working. I can connect to the management interface and web client by the IP address that I'm using on the phone, so I know the IP is correct and that other open ports on the firewall are working. Any ideas? At this point I'm thinking it's some advanced setting or combination of them, on the app account settings. Just don't know which ones.

Is there any logs I can check on the server to see if there are failing connection attempts? I should have SSH access to the machine, but I confess I haven't tried or confirmed yet.
 
Have you unticked 'Block Remote Tunnel Connections (3CX Client connections with Tunnel enabled & SBC will be blocked)' under options for each extension.

If you untick this, check your Blacklist and remove any IP's
 
Have you unticked 'Block Remote Tunnel Connections (3CX Client connections with Tunnel enabled & SBC will be blocked)' under options for each extension.

If you untick this, check your Blacklist and remove any IP's
The default for the Extension setting of "Use 3CX Tunnel for remote connections (3CX Client only) " is already checked. And the app also has a setting for "Use 3CX Tunnel. For that specific setting, there is another field for a password. Is that the same password that the extension uses, or something unique and specific to the 3CX Tunnel object?
 
There is another place, as per info above which needs unticking

Under the options tab


9698
 
Tunnel has a separate password, but if you provision the phone using the email config file or QBR code it will contain everything required.

Tunnel password is under Settings -> Security Settings - 3CX Tunnel
 
Tunnel has a separate password, but if you provision the phone using the email config file or QBR code it will contain everything required.

Tunnel password is under Settings -> Security Settings - 3CX Tunnel

Found it, thank you. Unfortunately, not the solution. Still not able to connect.

Regarding the QR code...I'm using it, but then having to change the "external PBX IP" because the DNS is wrong. Reason is, for some reason the first provisioning of the PBX in AWS failed...but not after a DNS record had been created. A re-provisioning succeeded, but the AWS Instance was provisioned with a completely new IP address, as the original one was terminated. I of course don't have access to the DNS records, but also don't appear to have any avenue to any kind of support, as I'm really just new to setting this up for a small business of mine. I have some PBX experience in the past, but am by no means an expert. I'm more of a networking/SysAdmin type.

Anyhow, the question is....is there anything about the DNS name not being right that would keep the phone from provisioning, like a certificate error or something because the name isn't matching with what the PBX thinks its name is (the incorrect DNS name)?
 
There is another place, as per info above which needs unticking

Under the options tab


View attachment 9698
I found this and confirmed that this is not unchecked, so Tunnel Connections should be allowed as far as I can see.
 
Are you using 3CX FQDN ?.

If the wan IP address changed, it can take 6 hrs for the change to be picked up. Under Settings - Network Settings , do you Static IP ticked and does this match your wan IP address ?

The phones provision via https, so the FQDN does have to match the wan IP address.
 
Problem solved...sort of. I took my phone off wifi and it connected, so it's either my router or ISP that is the problem.
 
On the router, are you blocking outbound ports - you need ports 5090 tcp / udp and 443 open
 
I found another thread that directed me to add a "port range trigger" on my router for port 5060. It's working now. Still can't make outbound calls (inbound works) but that's another problem altogether :)
 
  • Like
Reactions: YiannisH_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,914
Messages
589,712
Members
164,785
Latest member
Texas Clay -