Firewall ports differ between 3CX and Voiceflex Trunk

Status
Not open for further replies.

Mark Phillips

Customer
Advanced Certified
Joined
Jan 28, 2019
Messages
154
Reaction score
53
I have Voiceflex SIP trunks (one of the supported providers in the UK) and their tech support has advised that I need to permit the following traffic incoming from their IP range (a /24 network and a /26 network):

port 5060 – UDP/TCP
ports 10000 - 60000 - UDP

However, the RTP ports above are not the same as the normal 3CX range - 9000 - 10999.

What is the correct way of doing this? I don't use direct SIP and therefore have no need to leave 5060 and the RTP ports open to the internet, but setting the above 10000-60000 range looks like it might be a conflict with 3CX. Or do i not need to worry, as I still have ports 10000-10999 available, which still effectively has capacity for up to 500 simultaneous calls?
 
We use voice flex on 3cx hosted, so guessing the configuration has the correct firewall ports open as per https://www.3cx.com/docs/ports

Have the firewall test passed, if it does I would not worry about the ports
 
When I locked down 5060 to Voiceflex's IP ranges, the firewall check reported a failure on 5060 and the RTP ports. At that point, calls (via the SIP trunk) were working fine. I therefore presumed that the firewall check relies on the ports being open to internet traffic, not locked to a specific provider. It's a bit tricky to test further as it's a production system so I couldn't leave it in that state for long.

I will set up a test system to carry out further testing, but it would be good know what the correct process should be.
 
Yes, locking down the sip port 5060 to voiceflex with cause an issue with the firewall test

You could remove the restriction temporary and then run the test
 
Up until now, I've always had 5060 and the RTP ports open to any internet source, so the firewall check has always succeeded.
 
I have Voiceflex SIP trunks (one of the supported providers in the UK) and their tech support has advised that I need to permit the following traffic incoming from their IP range (a /24 network and a /26 network):

port 5060 – UDP/TCP
ports 10000 - 60000 - UDP
They must be referring to their own source ports meaning this is actually outbound traffic for you and incoming for them. The ports require by 3CX are the ones @Saqqara linked to here.
 
Thanks.

So, do I maintain a firewall rule which permits incoming 9000-10999 UDP only from voiceflex's IP range?

I see no reason to have 9000-10999 UDP (and 5060) open to the whole internet if it can be locked down?
 
So, do I maintain a firewall rule which permits incoming 9000-10999 UDP only from voiceflex's IP range?

I see no reason to have 9000-10999 UDP (and 5060) open to the whole internet if it can be locked down?
Since these ports are forwarded to the PBX IP then you should be able to just leave them open for the whole internet since 3CX will reject any traffic to these ports that is not part of an active session.
If you want to lock your firewall down then you will need to test everything carefully and maintain it since providers also change IPs.
 
Thanks.

So, do I maintain a firewall rule which permits incoming 9000-10999 UDP only from voiceflex's IP range?

I see no reason to have 9000-10999 UDP (and 5060) open to the whole internet if it can be locked down?
Do so at your own risk. Ultimately it depends on where the voice is coming from. Some providers stay in the audio path so the RTP would come from their IP range. Others don't stay in the audio path which means the RTP wouldn't be coming from their IP ranges necessarily.
 
firewall rule which permits incoming 9000-10999 UDP only from voiceflex's IP range
Note the ports document says "if you intend on using remote extensions, WebRTC or a VoIP Provider" for that range. You only mentioned not using direct SIP.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,973
Messages
590,075
Members
164,895
Latest member
jasonkkrause