Firewall and STUN: need some clarifications (no SBC)

Status
Not open for further replies.

Chrischevy80

Free User
Advanced Certified
Joined
Oct 1, 2017
Messages
37
Reaction score
4
After completing all three 3CX certifications and doing some research in the forum, it seems like a lot of people get confused (including me) when it's time to configure a router in a STUN + Cloud Hosted PBX environnement

My Setup:
A couple of phones on the LAN + a 3CX server hosted at OVH

My Firewall: PFSense
Incoming ports that I opened: none

I provisioned a few phones with Direct SIP (STUN remote), left all port default (SIP 5065 and RTP 14000-14019) and all seems to be fine.
The only option I had to enable on extenions is "PBX Deliver Audio", because phones have no clue how to re-invite each other without a SBC.

Why would I need to forward different incoming SIP ports for all my phones when the phone initiate a SIP connection toward 3CX and source ports a rewritten with a random port by the router ?

The PBX knows how to reach the phones via the public IP and the random port:
Example: Extension 103 is registered, contact: sip:[email protected]:20106
The router takes care of the rest in it's NAT table (forwarding external incoming port 20106 traffic to internal IP of the phone on right port)

So again, my question is: why would I need to forward any ports on my firewall ?

Another setting that I usually change in this kind of setup (on another evil PBX kind) is the SIP registration Timeout. It's usually set at 3600 and I lower it to 60 seconds so the registration doesn't get killed by the TCP/UCP timeout in the router. On 3CX, it seems to be set the 120 seconds, which is probably fine for remote extensions.
 
The problem that happens is "no audio", usually incoming, and usually on incoming calls. This can happen on calls between extensions, at the remote end, or from a n extension at the server end to the remote extension. Much can depend on the router at the remote end. Some seem to keep track of the audio port better than others. One, or a couple of extensions, may experience no issues, it is usually when you start to go beyond that, that problems begin. Every situation is going to be different, with the hardware used.

While "PBX delivers audio", will help, in most cases (to a point), it also eats up bandwidth, if a lot of calls are internal.
 
The simple answer is 3CX instructions are for the lowest common denominator. They can't control the firewalls people use and not all firewalls behave correctly. So while many times you don't NEED to configure the router per the STUN guide and things will work if you configure the router per the STUN guide things should ALWAYS work.
 
  • Like
Reactions: YiannisH_3CX
Hello @Chrischevy80

As mentioned not all firewalls are able to keep track of the audio and Sip ports each phone uses and that is where you start having problems with audio and some times registration.
The best way to handle STUN extensions is to assign unique ports to each set and port forward them to the phone's IP. That way you can scale your installation and keep track of the ports. Also easier to troubleshoot an issue when you know the ports used by each extension.
 
  • Like
Reactions: Chrischevy80
Status
Not open for further replies.

Forum statistics

Threads
111,889
Messages
589,580
Members
164,755
Latest member
adrhoades