Customer Firewall Rules

Status
Not open for further replies.

rjones

Silver Partner
Basic Certified
Joined
May 10, 2023
Messages
12
Reaction score
3
Hi,

I am setting up hosted 3CX and would appreciate any advice on the firewall ports required to be opened at the customers end. They also have a SBC capable phone on-site.

Looking at the docs - I am thinking the following:-

Source : Phone System IP Address
Destination : Customers SBC
Ports : tcp-443, tcp-5001, tcp-5090, udp-5090

Source : Customers LAN
Destination : Phone System IP Address
Ports : tcp-443, tcp-5001, udp-5090, tcp-5090

Also, do we need to open port 5060?

Thank you in advance
 
If it is not provisioned then it means the phones does not have outbound internet access, to the known 443 TLS port of the PBX.

They should allow access via their rules rather than forwards.
Forwards = the IP phone's port 5090 and 443 are accessible from the internet, which is not what we want here.

1. So I'd say remove any unnecessary forwards done, and first confirm whether the Phone has internet access.

2. Then confirm the firmware is correct, because it is known that trying to provision a SBC phone without correct firmware will lead to the office public IP being blocked on the PBX blacklist. This is a number one reason for SBC phone failures.

@rjones confirm that the phone has firmware 96.86.0.74 from the guides I shared. Then check on the PBX blacklist that your WAN IP has not been blacklisted. Confirm that you followed the guide and actually logged in the 3CX webclient, then clicked admin, then added the phone as a router phone per the guide. We need to confirm this first before looking at the firewalls etc.
Thank you. I can confirm the phone is on the correct firmware and is not blacklisted. I have been through the guides to ensure the configuration is correct.

The ISP will only allow access via their rules rather than forward.
 
Ok you are good then - but the firewall rules need to be relaxed for the phones.

They need access to NTP, TLS, TCP outbound and they probably aren't allowing this now.

You need to adjust the firewall ACL for this, and if you don't control the firewall then the responsible party needs to intervene to take care of this.
Thank you - your time is much appreciated. Can you confirm this is correct?

Source : LAN
Destination : Hosted Phone System
Ports : tcp-443, udp-5090, tcp-5090
 
Sorry, that is what I wanna say. The firewall need to be free outgoing for this ports. My english isn't that good.
 
@rjones - I'm not sure that will work - you need to allow it to access the internet freely.

IP phones perform a number of functions before they can provision and work. They need access to:
  1. DNS
  2. NTP
  3. Yealink's RPS server during provisioning
  4. The 3CX Server over 443 / 5090 for provisioning and SBC
  5. But also it will need to receive traffic from random PBX ports during the calls
If you lock it down to specific ports only, I'm afraid it will not work correctly..

If there are security considerations, then either the phones need to go on a separate network, or the customer should use a local dedicated PBX so all the traffic stays in-house.
 
Last edited:
  • Like
Reactions: rjones and bitn2
@rjones - I'm not sure that will work - you need to allow it to access the internet freely.

IP phones perform a number of functions before they can provision and work. They need access to:
  1. DNS
  2. NTP
  3. Yealink's RPS server during provisioning
  4. The 3CX Server over 443 / 5090 for provisioning and SBC
  5. But also it will need to receive traffic from random PBX ports during the calls
If you lock it down to specific ports only, I'm afraid it will not work correctly..

If there are security considerations, then either the phones need to go on a separate network, or the customer should use a local dedicated PBX so all the traffic stays in-house.
Thanks all - I've just been back on-site and all is now working well by applying the above rules.
 
  • Like
Reactions: JohnS_3CX
Hiya, I've just read this thread and am slightly confused that advice has gone from
" If the PBX is hosted by 3CX, we take care of the firewall rules at the server end."
to
"They need access to NTP, TLS, TCP outbound and they probably aren't allowing this now.
You need to adjust the firewall ACL for this, and if you don't control the firewall then the responsible party needs to intervene to take care of this."

I have an install next week and someone else looks after the site I.T - i would like to avoid the situation rjones found themselves in, so want to e-mail the I.T company in advance requesting whatever will ensure there is no problem caused by their firewall. I have read the guides but most of it seems to be for on premises. Please advise

My install will be hosted by 3cx with mix of Fanvil X6u X4u and X3u planning on one of those handsets being the SBC. they'll also have some windows app and mobile apps too. Thanks very much
 
@RichT Most sites allow all outbound traffic by default, and perhaps block unwanted traffic. If that is not the case and the site only allows specific outbound connections, then outbound traffic for the phones and to the 3CX server needs to be allowed.

Inbound traffic at the 3CX server end is handled by 3CX if they are hosting the server.
 
  • Like
Reactions: RichT and bitn2
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet