Connection issues with 3CX Boarder controller

Status
Not open for further replies.

Glen3cxNZ

Customer
Joined
Sep 2, 2016
Messages
14
Reaction score
8
Hi We are having connectivity issues with 4 of our sites connecting by 3CX border controller back to the server this morning, It appears to be since 4am that the SBC lost connection to the 3CX server.

The SBC log shows the following error

ERR | 20170626-042755.827 | 3CXTunnel | TUNL | 5872 | TunnelTcp.cpp:262 | Bridge [3CXSBC15.0.61335] failure 'TLS handshake failed: error:00000001:lib(0):func(0):reason(1)
+ (err): error:00000001:lib(0):func(0):reason(1)' on TCP connection: secure negotiation

Restarting the 3CX server or Session broker has not fixed this issue.

Has anyone else seen this issue?

Update... I have heard back from my 3CX support ticket and they investigating this internally as the issue appears to be a global one. I have provided them with some logs so I hope they will come up with a solution soon. My advise to anyone with this issue its to temporarily disable encryption from the SBC. change the SecurityMode=1 to SecurityMode=0 in the SBC config file and restart the sbc service . I suspect we will see a new SBC build soon to fix this.

I hope this has been helpful for others.

Additional Update
Here are instructions from 3CX Support for the workaround on windows and Linux

Hello all,

Here are details on how to disable the encryption so you can bypass the issue for now

Windows SBC
  1. Stop the 3CX SBC Service from the Windows Services.
  2. From the start menu find "Notepad", right-lick and select "Run as Administrator".
  3. Find line:
    SecurityMode = 1
    and change to:
    SecurityMode = 0
  4. Save the file.
  5. Restart the SBC service.
  6. Allow up to 10 minutes for the phone to re-register.

Debian or Raspberry Pi SBC
  1. Access the SBC machine via SSH and switch to the root user.
  2. Type: service 3cxsbc stop
  3. Type: nano /etc/3cxsbc.conf
  4. Find line:
    SecurityMode = 1
    and change to:
    SecurityMode = 0
  5. Save the file by pressing Ctrl + X, then press 'y', then hit Enter.
  6. Type: service 3cxsbc start
  7. Allow up to 10 minutes for the phone to re-register.
We apologize for the inconvenience that his has caused you and we will try to solve this as soon as possible.
 
Last edited:
Hi,

I'm having this same problem.

Seems like a TLS\SSL problem.

A work around I'm using is changing SecurityMode=1 to SecurityMode=0 in the SBC config file.

Still haven't got a fix found yet though, anyone else got any ideas?

My Certs are valid, time is right on both ends, and we're using the correct domain name to connect.
 
  • Like
Reactions: CentrexJ
Same problem here 2 different phone systems since this morning. SecurityMode=0 fixed it for both.
TLS cert expired???
 
I've got same issue - all SBC sites down.
Changing SecurityMode=1 to SecurityMode=0 in the SBC config file is a workaround.

Appears to be an issue with the embeded SSL in SBC.
 
Yes i disabled encryption and the SBC's are connecting again. Most Frustrating. Anyone heard from 3CX?
 
This is a "Me too" post.

2 sites down due to the same issue. SecurityMode=0 fixed it for me as well
 
Hi,

I'm also having the same issue with the Windows version of the Session Border Controller at multiple locations connecting to a cloud hosted instance of 3CX Phone System.

I had also managed determine that setting SecurityMode=0 in the 3cxsbc.conf was a work-around for the problem.

I came here to create a post about this issue and then came across this post.

There were no posts when I first came across the issue earlier today Australian time, as I checked the forums before getting further into debugging the issue.

I upgraded our 3CX Phone System to version 15.5 after the close of business on Friday so initially I wasn't sure if the issue was related to the upgrade of the 3CX Phone System.

I'm currently using version 15.5.1136.6 of the 3CX Session Border Controller (which appears to be the latest version) at each location. I upgraded each location to this version as part of debugging of the issue.

We are using version 15.5.1694.0 of 3CX Phone for Windows on the PCs at these locations and they don't seem to have any issues connecting to the same 3CX Phone System via the 3CX Tunnel so the issue seems to be with the 3CX Session Border Controller and not the 3CX Phone System.

The iOS and Android apps also don't seem to have any issues connecting via the 3CX tunnel over Wi-Fi from the same locations.

I enabled DEBUG level logging on the 3CX Session Border Controller at one location and ran the 3CX Session Border Controller service for 5 minutes so I could capture a DEBUG log which I've attached to this post.

As 3CX are based in the UK we'll probably have to wait for them to get in later today before we get a response.

Les
 

Attachments

Last edited:
Thanks for your reply.
I too had gone through those same troubleshooting tests with the same results. Yes the mobile clients and stun connected phones work fine . the issue only appears to be with the 3cx Session boarder controller and i agree with the others on this post that it appears to be something to do with the embedded SSL expiring in the SBC?

As I am NewZealand based we were most likely the first in the world to come across this problem. Which appeared at 4am this Morning after the SBC automatically restarted.

We had no phones for four of our Clients for almost 3 hours while we worked on the problem.

I am disappointed with 3CX support .I have called my local 3cx Support and logged a ticket with 3cx over 4 hours ago and still no answer from either. Just had to find the workaround ourselves.
 
Update... I have heard back from my 3CX support ticket and they investigating this internally as the issue appears to be a global one. I have provided them with some logs so I hope they will come up with a solution soon. My advise to anyone with this issue its to temporarily disable encryption from the SBC . I suspect we will see a new SBC build soon to fix this.

I hope this has been helpful for others.
 
Ok thanks for share the infos here.
We also fixed the issue with setup securityMode = 0.

This thread save my monday business start, because i can fix the problem before the rest of our office beginn with working day. :)
 
We are checking - yes probably certificate related. Bear with us guys.
 
Same problem here for a number of clients, changing to 0 has not helped. All clients went off at around 3-4pm NZ time
 
@nicknz
Do you have restart the 3cxsbc-service?
We also fixed this with "securityMode = 0"
 
You have to restart the sbc service after changing to 0.
 
I am also seeing the same issue, disabling encryption allows SBC to connect.

Waiting for an update from 3CX.
 
Same here today. Client with 2 sites which are using SBC gone down. it's strange how all of the sudden same thing happened to a lot of people over night! think 3cx has to do some explaining!
 
Yup Same issue here. Logged a ticket with 3cx. Changing the config file has got clients re-connected in the meantime
 
This is having quite a big impact across our sites. Do you @3cx have an ETA on a permanent fix?
 
Same issue here affecting a large number of locations! Disabled encryption as a work around.
 
Does anyone have a guide for this workaround please?
 
Status
Not open for further replies.

Forum statistics

Threads
112,063
Messages
590,574
Members
165,019
Latest member
rsaldin@advancedbrainspin