ERR_SSL_PROTOCOL_ERROR

Status
Not open for further replies.

TonyLoftus

Bronze Partner
Basic Certified
Joined
Nov 17, 2020
Messages
25
Reaction score
3
Hi All,

I recently carried out my first fresh install. The system is 90% working but when trying to access the FQDN, I get the above error in chrome. Edge browser elaborates slightly further - "The
connection for this site is not secure"

The phone system is running on a new Intel nuc, which is running the 3cx debian linux software. 3cx version 16.0.8.9
I used a USB-C to ethernet adaptor as the onboard NIC wasn't supported during the installation. Default ports for everything are being used, and I'm not using a 3rd party for the FQDN. There were no errors during the installation. The router is a microtik which I don't have access to, only the ISP does. They were reluctant to open all the ports for the media s erer (9000-10999) So at the moment, the firewall does pass the checks up to the media server ports. I have bene told that they would open the media server ports if requested. They just didn't think the end client would be needing them (they could well be right)

The ISP assures me, that 5001 is open, which I assume is correct as the error is not a timeout error. I enabled the instance manager for this install, which I assume is working? I can access the instance manager from our reseller portal, but it looks like I can only "add note"

Licence is annual, and is a professional licence. Initially, a trial licence was generated so I could do some initial testing before I took all the hardware to site. This was then converted to a professional licence as guided by our reseller partner.

Aside from doing a backup and reinstallation, I don't really know what else to do. I've done a bit of googling and read a few threads on this message board, but hadn't really come across anything that seemed to fit my current situation. I have logged a support request with our reseller partner and their tech support, but I figured it couldn't hurt to post here as well.

Thanks,
Tony
 

Attachments

  • 3cx error - SSL.PNG
    3cx error - SSL.PNG
    18.8 KB · Views: 11
  • 3cx firewall 30.7.PNG
    3cx firewall 30.7.PNG
    60.1 KB · Views: 11
Could you provide the following information to allow us to get a better understanding of the situation:

1. I see you can access the Management Console as you have ran the firewall checker. Was this using the IP of the PBX? If yes, which one and from where, did you use the local ip from within the same LAN as the pbx or the public IP from a remote site?

2. When you use the FQDN and get the error, are you trying this from the same LAN as the PBX is in? If yes, do you still get it if you try from a remote network(say a mobile data connection)?

3. When you try with the FQDN, make sure you're specifying the correct port (5001 in your case) such as: https://<FQDN>:<PORT>

4. Try the FQDN again and check the certificate in the upper left corner, does it say that it's valid?:

• Click on the lock icon and then on "Certificate"
1628164512663.png

• Does "Issued to" show your FQDN and "Valid from/to" show valid dates?
1628164605648.png

5. Is the System Date/Time on the PC you're trying to access the Management Console from correct?
 
Could you provide the following information to allow us to get a better understanding of the situation:

1. I see you can access the Management Console as you have ran the firewall checker. Was this using the IP of the PBX? If yes, which one and from where, did you use the local ip from within the same LAN as the pbx or the public IP from a remote site?

2. When you use the FQDN and get the error, are you trying this from the same LAN as the PBX is in? If yes, do you still get it if you try from a remote network(say a mobile data connection)?

3. When you try with the FQDN, make sure you're specifying the correct port (5001 in your case) such as: https://<FQDN>:<PORT>

4. Try the FQDN again and check the certificate in the upper left corner, does it say that it's valid?:

• Click on the lock icon and then on "Certificate"
View attachment 23370

• Does "Issued to" show your FQDN and "Valid from/to" show valid dates?
View attachment 23371

5. Is the System Date/Time on the PC you're trying to access the Management Console from correct?
Hi Chris,

Will answer these as best I can:

1. I see you can access the Management Console as you have ran the firewall checker. Was this using the IP of the PBX? If yes, which one and from where, did you use the local ip from within the same LAN as the pbx or the public IP from a remote site?

Yes I ran the firewall checker from the management console. I was connected to the local LAN at the time, and was using the local static IP address for the pbx


2. When you use the FQDN and get the error, are you trying this from the same LAN as the PBX is in? If yes, do you still get it if you try from a remote network(say a mobile data connection)?

So far, I have only tried accessing the FQDN from outside the LAN. I can't access it from my office, or at home (using wifi)



3. When you try with the FQDN, make sure you're specifying the correct port (5001 in your case) such as: https://<FQDN>:<PORT>

yes I'm doing this. I blanked out the url in the screenshot as I've seen previous posts on this messageboard where people have done the same thing


4. Try the FQDN again and check the certificate in the upper left corner, does it say that it's valid?

No, the only thing I get in the upper left corner is that the connection isn't secure

5, Yes the laptop I'm using has the right time and timezone
 

Attachments

  • 3cx error ssl.png
    3cx error ssl.png
    14.8 KB · Views: 7
  • 3cx SSL error.png
    3cx SSL error.png
    38.6 KB · Views: 8
So far, I have only tried accessing the FQDN from outside the LAN. I can't access it from my office, or at home (using wifi)
Could you try using the public IP instead of the FQDN and tell me what happens?

HTTPS://<PUBLIC_IP>:<HTTPS_PORT>
 
Exact same result. Blanked one octet out.
 

Attachments

  • fqdn issue.png
    fqdn issue.png
    14.3 KB · Views: 5
Try accessing it from the Local LAN again with HTTPS://<LOCAL_IP>:<HTTPS_PORT>
Then, check the certificate information as per my first reply, if everything seems correct, it must be something to do with the mikrotik's configuration.
 
Thanks Chris. I will check that out when I next go onsite.
 
  • Like
Reactions: ChrisC_3CX
Understood! Do let us know how it goes!
 
Hi Chris,

I have just tried this now via teamviewer instead. Hopefully thats ok. I used the local lan ip address and the port on the end. Although it says unsecure, I can access everything.

Our own 3cx system acts the same way when accessing via the local lan. I can still access our management console via the FQDN link both inside our LAN and outside it though.
 

Attachments

  • strong 3cx certificate.png
    strong 3cx certificate.png
    45.8 KB · Views: 7
  • strong local IP + port.png
    strong local IP + port.png
    33.9 KB · Views: 7
Last edited:
In that case, it must have something to do with the mikrotik's configuration so that's where I suggest you look next.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,982
Messages
590,116
Members
164,908
Latest member
FarizQasimov