DID Logic Call or Registration to DID Logic has failed.

Status
Not open for further replies.

cafecom

Customer
Advanced Certified
Joined
Aug 7, 2012
Messages
18
Reaction score
1
I am experiencing an issue with my SIP trunk to DID Logic. This is occuring on 2 seperate 3CX installations using seperate SIP trunks to DID Logic.

It appears to be similar to the report at https://www.3cx.com/community/threa...of-using-same-nonce-by-3cx.61476/#post-259536

I get the following sequence of email alerts from 3CX

1722hrs - Trunk L:10000(DID Logic) has changed status to unregistered. This means that no more calls will pass via this trunk. Please check your network connection and the voip provider or other SIP PBX
1722hrs - Call or Registration to DID Logic has failed. sip:[email protected]:5060 replied: 401 Unauthorized; from IP:119.9.12.222:5060
1727hrs - Trunk L:10000(DID Logic) has changed status to registered.

This happens regularly but inconsistently. Can be everyday or 7 days between.

I contacted DID Logic and they provided the following breakdown. PLEASE NOTE SOME DETAILS HAVE BEEN CHANGED FOR SECURITY REASONS.

"
As far as we can see from your recent REGISTER attempts your 3cx is not quite accurate with responses.
Here are our recent observations:

The first REGISTER from your end came as follows:
2019/10/15 22:47:16.512379 11.11.11.11:5060 -> 119.9.12.222:5060
REGISTER sip:sip.au.didlogic.net:5060 SIP/2.0
Via: SIP/2.0/UDP 11.11.11.11:5060;branch=z9hG4bK-524287-1---2b1a01725da5d777;rport
Max-Forwards: 70
Contact: <sip:[email protected]:5060;rinstance=8c28917ba30a4472>
To: "0298765432"<sip:[email protected]:5060>
From: "0298765432"<sip:[email protected]:5060>;tag=d006f548
Call-ID: KlYCUYjoomx8dVfipO5fww..
CSeq: 19 REGISTER
Expires: 120
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REGISTER, SUBSCRIBE, NOTIFY, REFER, INFO, MESSAGE, UPDATE
Supported: replaces, timer
User-Agent: 3CXPhoneSystem 16.0.3.676 (676)
Authorization: Digest username="99999",realm="sip.au.didlogic.net",nonce="XaZNn12mTHPsq7GAqX1XcXP6ZhYc3p8hkY/NWYA=",uri="sip:sip.au.didlogic.net:5060",response="8c66a5cd826b2cbe5553
8aaa7e3900",cnonce="f2272cbd33777276bc986fca73da9a9b",nc=00000001,qop=auth,algorithm=MD5
Content-Length: 0

Please note the following argument:
nonce="XaZNn12mTHPsq7GAqX1XcXP6ZhYc3p8hkY/NWYA="


We've answered 401 Unauthorized, as the previous REGISTER has expired:
2019/10/15 22:47:16.513598 119.9.12.222:5060 -> 11.11.11.11:5060
SIP/2.0 401 Unauthorized
Via: SIP/2.0/UDP 11.11.11.11:5060;branch=z9hG4bK-524287-1---2b1a01725da5d777;rport=5060;received=11.11.11.11
To: "0298765432"<sip:[email protected]:5060>;tag=b27e1a1d33761e85846fc98f5f3a7e58.0c2e
From: "0298765432"<sip:[email protected]:5060>;tag=d006f548
Call-ID: KlYCUYjoomx8dVfipO5fww..
CSeq: 19 REGISTER
WWW-Authenticate: Digest realm="sip.au.didlogic.net", nonce="XaZNoF2mTHS+WkIzbddf0PoWQgktRBLEkY/SXoA=", qop="auth"
Content-Length: 0

and we've provided you with the new nonce:
nonce="XaZNoF2mTHS+WkIzbddf0PoWQgktRBLEkY/SXoA="


Your 3CX has sent the second REGISTER attempt:
2019/10/15 22:47:17.512853 11.11.11.11:5060 -> 119.9.12.222:5060
REGISTER sip:sip.au.didlogic.net:5060 SIP/2.0
Via: SIP/2.0/UDP 11.11.11.11:5060;branch=z9hG4bK-524287-1---2b1a01725da5d777;rport
Max-Forwards: 70
Contact: <sip:[email protected]:5060;rinstance=8c28917ba30a4472>
To: "0298765432"<sip:[email protected]:5060>
From: "0298765432"<sip:[email protected]:5060>;tag=d006f548
Call-ID: KlYCUYjoomx8dVfipO5fww..
CSeq: 19 REGISTER
Expires: 120
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REGISTER, SUBSCRIBE, NOTIFY, REFER, INFO, MESSAGE, UPDATE
Supported: replaces, timer
User-Agent: 3CXPhoneSystem 16.0.3.676 (676)
Authorization: Digest username="99999",realm="sip.au.didlogic.net",nonce="XaZNn12mTHPsq7GAqX1XcXP6ZhYc3p8hkY/NWYA=",uri="sip:sip.au.didlogic.net:5060",response="8c66a5cd826b2cbe5553
8aaa7e3900",cnonce="f2272cbd33777276bc986fca73da9a9b",nc=00000001,qop=auth,algorithm=MD5
Content-Length: 0

As you can find, your 3CX has sent the same nonce which is incorrect and violates the RFC:
nonce="XaZNn12mTHPsq7GAqX1XcXP6ZhYc3p8hkY/NWYA="


Then we answered with 401 Unauthorized second time with new nonce:
2019/10/15 22:47:17.514141 119.9.12.222:5060 -> 11.11.11.11:5060
SIP/2.0 401 Unauthorized
Via: SIP/2.0/UDP 11.11.11.11:5060;branch=z9hG4bK-524287-1---2b1a01725da5d777;rport=5060;received=11.11.11.11
To: "0298765432"<sip:[email protected]:5060>;tag=b27e1a1d33761e85846fc98f5f3a7e58.0c2e
From: "0298765432"<sip:[email protected]:5060>;tag=d006f548
Call-ID: KlYCUYjoomx8dVfipO5fww..
CSeq: 19 REGISTER
WWW-Authenticate: Digest realm="sip.au.didlogic.net", nonce="XaZNoV2mTHUdH4OGmnABCDtMJA/g31A9kY/VYYA=", qop="auth"
Content-Length: 0

nonce="XaZNoV2mTHUdH4OGmnABCDtMJA/g31A9kY/VYYA="


and then your end provides us with the correct credentials:

2019/10/15 22:47:17.571450 11.11.11.11:5060 -> 119.9.12.222:5060
REGISTER sip:sip.au.didlogic.net:5060 SIP/2.0
Via: SIP/2.0/UDP 11.11.11.11:5060;branch=z9hG4bK-524287-1---55e7ce15e8487c26;rport
Max-Forwards: 70
Contact: <sip:[email protected]:5060;rinstance=8c28917ba30a4472>
To: "0298765432"<sip:[email protected]:5060>
From: "0298765432"<sip:[email protected]:5060>;tag=d006f548
Call-ID: KlYCUYjoomx8dVfipO5fww..
CSeq: 20 REGISTER
Expires: 120
Allow: INVITE, ACK, CANCEL, OPTIONS, BYE, REGISTER, SUBSCRIBE, NOTIFY, REFER, INFO, MESSAGE, UPDATE
Supported: replaces, timer
User-Agent: 3CXPhoneSystem 16.0.3.676 (676)
Authorization: Digest username="99999",realm="sip.au.didlogic.net",nonce="XaZNoV2mTHUdH4OGmnABCDtMJA/g31A9kY/VYYA=",uri="sip:sip.au.didlogic.net:5060",response="f274ea9da23e3a69aa6a
ef57a8f5ec",cnonce="929010be0df820c411f5bb40c1fc2820",nc=00000001,qop=auth,algorithm=MD5
Content-Length: 0


And we answer 200 OK:
2019/10/15 22:47:17.572946 119.9.12.222:5060 -> 11.11.11.11:5060
SIP/2.0 200 OK
Via: SIP/2.0/UDP 11.11.11.11:5060;branch=z9hG4bK-524287-1---55e7ce15e8487c26;rport=5060;received=11.11.11.11
To: "0298765432"<sip:[email protected]:5060>;tag=b27e1a1d33761e85846fc98f5f3a7e58.9275
From: "0298765432"<sip:[email protected]:5060>;tag=d006f548
Call-ID: KlYCUYjoomx8dVfipO5fww..
CSeq: 20 REGISTER
Contact: <sip:[email protected]:5060;rinstance=8c28917ba30a4472>;expires=120
Content-Length: 0


Please note, that 3 incorrect REGISTER attempts in a row lead to the temporary IP blockage due to security reasons for 5 minutes.

Then IP will be released from the blacklist.

As far as we see from now, that what has happened. Please check your 3CX settings.
"

My understanding from their response is that 3CX is using the same NONCE after it has expired. Then gets blacklisted for 5 mins. Then uses correct NONCE and all is ok until next time. I presume that there is a setting in the SIP config that might assist with this.

Thank you for any assistance you can offer.
 
Is anyone able to offer any advice or assistance with this?
 
Hi,

We would like to investigate this, but you have to provide us with the capture that contains the above.

Once you get the capture and confirm that it definitely contains this scenario, you can upload it somewhere and send me a private message so we can take a look.
 
JohnS,

Thank you for assisting. Perhaps you can offer some assistance to get the capture.

As the problem is intermittent it can be days between the disconnect occuring. And unlikely that I can successfully capture it within the 3CX console session. I did get some advice to run tshark from the linux environment but it was failing to run with the belo error.

tshark: The capture session could not be initiated on interface 'ens3' (That device doesn't support monitor mode).
Please check that you have the proper interface or pipe specified.
0 packets captured.

Thank you.
 
That's probably a wrong command issue, so I would suggest some Googling for your specific error.

Regardless, here is the commands I would suggest if you want to try again ( I don't know what you typed originally so just to be sure here's everything ). Make sure you log in with superuser rights to run your commands:

apt-get install tshark
mkdir pcap
chmod +7777 pcap
tshark -i any -b filesize:10240 -w pcap/capture.pcap

It will create 10mb files that you can delete every now and again to keep disk usage low until you catch the issue.
 
Thank you for the guide. I am now capturing packets and will hopefully get back to you tomorrow.

Regards
 
I believe I have captured an event. What is a secure way to provide the files?

Thanks
 
You can upload it somewhere publicly and send me the link in a private message

Include descriptions of the IPs and which call was the one that failed so we can look at it
 
I have messaged you a link.

Thanks
 
According to your capture we see the following - numbered with the packets in the PCAP

Existing Call ID - we will refresh our existing registration now
21797)We try to register using existing nonce from last 200 OK
21799)They send unauthorized and update the nonce
21802)We try to register using the updated nonce (and expecting a 200 OK)
21808)We again try to register using the updated nonce since there was no reply (and expecting a 200 OK)
21809)Instead of 200 OK they send unauthorized and update the nonce again even though the new nonce was used
21810)We try to register using the updated nonce (and expecting a 200 OK)
21911)We again try to register using the updated nonce since there was no reply (and expecting a 200 OK)
21812)Instead of 200 OK they send unauthorized and update the nonce again

At this point, after 3 attempts getting an unauthorized in the minute 11:21 we back off to avoid being banned. We will retry at minute 11:26 from the beginning with a new call ID

New Call ID - we make a new registration from the beginning
39893)We try to register from the beginning (no nonce, using new call ID)
39894)They send unauthorized and provide the nonce
39897)We try to register using the updated nonce (expecting a 200 Ok to come now)
39898)We get 200 OK as expected and become registered

Their above answer unfortunately does not address the why the PBX got no 200 OK reply when refreshing the existing registration, in my opinion this is the critical part that needs to be investigated above all else since it seems like the PBX is doing as it is told and updating the nonce correctly according to your own captures.
 
Based on the responses from DI Logic I want to implement Direct SIP calling.

I am looking for some advice on how to do that.

Thanks for any assistance.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,822
Members
164,814
Latest member
Ruben756