- Joined
- Aug 3, 2018
- Messages
- 10
- Reaction score
- 5
I have a confusing issue regarding Ports with 3CX and SIP trunk using a Dell Sonicwall -
It is well documented that the following standard firewall ports are required -
Port 5061 TCP only - Used for SIP TLS - not required for my system
Port 9000 - 9500 UDP only (some same 10999) - Used for RTP & WebRTC - essential my system
Port 5090 TCP & UDP - Used as a secure tunnel for 3CX apps from WAN - essential for my system
Port 5060 TCP & UDP - Used for the main signalling ports for the call - essential for our system
Port 5001 - Used for remote WAN management of the Web Interface - not required for my system (LAN admin only)
As it is said, these are the basic requirements and in reality, for testing, I have opened only 9000-9500, 5060 and 5090 - all directed in my Dell Sonicwall (through NAT & Access rules) at the 3CX Linux Server on the LAN at 192.168.1.98
All worked well in testing and then I selected my preferred SIP provider in the UK who instructed me the following -
"Please find the SIP endpoint information below along with the DID range. Please be aware that SIP ports 5060 UDP will need to be opened to the 88.215.58.15 & 88.215.58.16. You will also need to open TCP/UDP 6000 to 40000 to this same IP address."
So I modified the NAT policies and Access rules in the Sonicwall as follows:
Port 5090 accepts incoming from any WAN IP address and forwards to 192.168.1.98
Port 5060 only accepts incoming from WAN IP's 88.215.58.15 & 88.215.58.16 and forward to 192.168.1.98
Port Range 6000 to 40000 (i expanded the original 9000-9500) only accepts incoming from WAN IP's 88.215.58.15 & 88.215.58.16 and forward to 192.168.1.98
The internal system and SIP trunks are working fine but now the 3CX and other mobile phone apps working over 4G or WAN cannot connect or make calls. They show as disconnected.
The question I have is regarding the 3CX dedicated mobile App and Windows App use of Port 5090 as a secure tunnel. Is this 5090 for the signalling only or including the Audio as well down the tunnel? If the app needs to use other ports apart from 5090 then how is this going to work when the 5060 and the range 6000 to 40000 only receive incoming for these two approved WAN IP's?
The second question is that the external WAN 3CX apps on both PC and Mobile do not show the extension list with the usual Green Busy lamp ans the call log is also not saving for redial. Is this a setting I am missing in the extension settings or is this needing one of the other ports opening in the firewall?
It is well documented that the following standard firewall ports are required -
Port 5061 TCP only - Used for SIP TLS - not required for my system
Port 9000 - 9500 UDP only (some same 10999) - Used for RTP & WebRTC - essential my system
Port 5090 TCP & UDP - Used as a secure tunnel for 3CX apps from WAN - essential for my system
Port 5060 TCP & UDP - Used for the main signalling ports for the call - essential for our system
Port 5001 - Used for remote WAN management of the Web Interface - not required for my system (LAN admin only)
As it is said, these are the basic requirements and in reality, for testing, I have opened only 9000-9500, 5060 and 5090 - all directed in my Dell Sonicwall (through NAT & Access rules) at the 3CX Linux Server on the LAN at 192.168.1.98
All worked well in testing and then I selected my preferred SIP provider in the UK who instructed me the following -
"Please find the SIP endpoint information below along with the DID range. Please be aware that SIP ports 5060 UDP will need to be opened to the 88.215.58.15 & 88.215.58.16. You will also need to open TCP/UDP 6000 to 40000 to this same IP address."
So I modified the NAT policies and Access rules in the Sonicwall as follows:
Port 5090 accepts incoming from any WAN IP address and forwards to 192.168.1.98
Port 5060 only accepts incoming from WAN IP's 88.215.58.15 & 88.215.58.16 and forward to 192.168.1.98
Port Range 6000 to 40000 (i expanded the original 9000-9500) only accepts incoming from WAN IP's 88.215.58.15 & 88.215.58.16 and forward to 192.168.1.98
The internal system and SIP trunks are working fine but now the 3CX and other mobile phone apps working over 4G or WAN cannot connect or make calls. They show as disconnected.
The question I have is regarding the 3CX dedicated mobile App and Windows App use of Port 5090 as a secure tunnel. Is this 5090 for the signalling only or including the Audio as well down the tunnel? If the app needs to use other ports apart from 5090 then how is this going to work when the 5060 and the range 6000 to 40000 only receive incoming for these two approved WAN IP's?
The second question is that the external WAN 3CX apps on both PC and Mobile do not show the extension list with the usual Green Busy lamp ans the call log is also not saving for redial. Is this a setting I am missing in the extension settings or is this needing one of the other ports opening in the firewall?
Last edited: