Solved Extensions won't register after the office IP address changed

Status
Not open for further replies.

rudek

Free User
Joined
May 15, 2012
Messages
22
Reaction score
0
We have our 3CX on AWS with a public IP address and a FQDN. Our LAN Phones in the office are behind the office piblic IP address and access the services using the FQDN in all their settings. We also have a few 3CX Windows clients installed on PCs. It all worked fine for over a year until today our ISP had a failure and we changed to a different ISP, which also changed the public IP address of our office. So all LAN phones extensions now try to access the 3cx server from a different public IP and they all failed to register, all 3cx Windows phones register fine.

All LAN phones are allowed to access "outside of LAN" (i.e. the Disallow use of extension outside the LAN is unchecked) and all firewalls on the route do not block any IP addresses involved. The only thing that changed is the public IP address of the phones accessing the AWS-based 3CX.

We expect we will have to alternate our public IP address until we wind a better ISP. Does anyone know how to make this work?

Thanks in advance,
Rudy
 
First, verify that the new IP hasn't been blacklisted by the 3CX. It shouldn't since the 3CX Client registers but check anyway.

Then, I would try to reprovision all phones and test that the FQDN is reachable by the phones (run a packet capture to be sure).
 
How where the phones provisioned - stun or sbc

As your ISP has changed, have you checked all your firewall rules

Look into one of the phones web front end, and confirm it is using fqdn and not up address

Have your dns servers changed, I would always use 8.8.8.8 and 8.8.4.4

Have you tried to restart one of the phones

Can you ping the fqdn and does it point to correct IP address
 
Last edited:
Another thing: check your firewall rules on AWS. You might be filtering the 5060 port to the public IP of the old ISP. You'll need to change that to the new one.

3CX Clients works because they use the tunnel directly. (Port 5090)
 
Hi guys, thanks for the quick answers...
  • no, the new IP is not blacklisted on 3CX, nor on the server's firewall, nor on the AWS security group
  • there are no firewall rules that would include any ISP settings :(
  • the phones are provisioned via Stun
  • FQDN is reachable by various other office PCs, etc. I am not sure how to check that from the phones. Those are Htek 924's and 926's.

Hope this info helps to localize the issue...
 
Hi guys, thanks for the quick answers...
  • no, the new IP is not blacklisted on 3CX, nor on the server's firewall, nor on the AWS security group
  • there are no firewall rules that would include any ISP settings :(
  • the phones are provisioned via Stun
  • FQDN is reachable by various other office PCs, etc. I am not sure how to check that from the phones. Those are Htek 924's and 926's.
Hope this info helps to localize the issue...
If the issue isn't firewall related, I'd try to simply factory reset one phone then reprovision it using STUN. Reboot the phone and RPS should do its job.

What is the firewall brand in the office?
 
firewall is a pfsense. It has no settings for 3CX at all because 3CX is not located in our office but on AWS. So it should be transparent.

Ok, I will try to reset one phone and see if it will connect. But I expect that we will have to change office IPs a few times in the next weeks, so a more robust solution would be nice.

Thanks again!
 
firewall is a pfsense. It has no settings for 3CX at all because 3CX is not located in our office but on AWS. So it should be transparent.

Ok, I will try to reset one phone and see if it will connect. But I expect that we will have to change office IPs a few times in the next weeks, so a more robust solution would be nice.

Thanks again!
Unless there are firewall rules or something like that, it shouldn't cause any issues.

Normally, if you use the FQDN in STUN, phones should reconnect automatically. What you're experiencing is weird.
 
I know, by all logical thinking it should work, but it does not...
 
I know, by all logical thinking it should work, but it does not...
Like I said, try a factory reset. Also, I'd try rebooting the office router just in case, to be safe.
 
will do tomorrow on the phone. The office has no router per se, only a firewall. Let's see what happens.
 
will do tomorrow on the phone. The office has no router per se, only a firewall. Let's see what happens.
A pfSense firewall becomes the router in that case. But yeah, just try to reboot it. Sometimes the ARP cache and DNS cache and things like that can cause lots of issues.

By the way, how many phones are on the office side? If more than 2-3, I'd go with an SBC for better reliability.
 
  • Like
Reactions: AWS2P
Hi Frederick,
we rebooted the pfsense once. Without doing anything else, the LAN-based desk phones connected to 3CX, but we had no outgoing audio from the phones to the outside world. Then rebooted pfsense once more and audio started working. So this helped, many thanks!
Rudy
 
Glad to see the issue has been resolved. Some times when your public IP changes the modem/firewall has the old public IP cached. So when the phone creates a STUN request it gets back the old IP so the PBX does not know how to reach the phone. A reboot of the modem/firewall can solve this issue.
 
Status
Not open for further replies.

Forum statistics

Threads
111,933
Messages
589,809
Members
164,808
Latest member
jsbjsb