Firewall ports requirement if using PRI

Status
Not open for further replies.

Kane Wong

Free User
Joined
Oct 13, 2018
Messages
233
Reaction score
9
Hello;

I would like to confirm if only port 5060 and port 5001 are required to be open on my firewall for inbound to meet my requirement below. I am using PRI and the Analog connection with 3CX, not SIP Trunks.

Requirement
  1. Allow 3CX mobile app to be used remotely by users. (Through public internet)
  2. Allow access to the 3CX web client from remote site through public internet.

If port 9000-10999 are for the SIP Trunks only?
 
Another way to look at it is where is your gateway in relation to the 3CX server. If there's no firewall between them.....
 
Hello;

I would like to confirm if only port 5060 and port 5001 are required to be open on my firewall for inbound to meet my requirement below. I am using PRI and the Analog connection with 3CX, not SIP Trunks.

Requirement
  1. Allow 3CX mobile app to be used remotely by users. (Through public internet)
  2. Allow access to the 3CX web client from remote site through public internet.
If port 9000-10999 are for the SIP Trunks only?
You will need 5090 for the mobile apps to register via the tunnel, and 5001 or 443 depending on what is configured as the HTTPS port on your server. 5060 will not be required as your not using SIP trunks.
 
It seems, the port 9000-10999 is required even though I am using PRI because when using mobile phone, the calls between extension to extension is through internet.
 
It seems, the port 9000-10999 is required even though I am using PRI because when using mobile phone, the calls between extension to extension is through internet.
On the mobile app, all traffic is sent over 5090 I believe. You would only need these ports if you had devices on STUN.
 
  • Like
Reactions: JohnS_3CX
It seems, the port 9000-10999 is required even though I am using PRI because when using mobile phone, the calls between extension to extension is through internet.
13816

I'm not seeing 9000-10999 in this diagram.....

That being said, 3CX has wavered back and forth on this quite a bit. Originally, the apps only used to use the tunnel. Then back in v14 I think they started defaulting to direct SIP and then failing over to the tunnel if need be. It defaults back to the tunnel now so you should just need the ports listed above, which again, doesn't include 9000-10999
 
The best way to look at this is in the format of legs of calls.

So when using a PRI gateway connection since it should be setup either locally to the PBX or across a VPN connection no port requirements are needed for the outbound ISDN connection (obviously) or the connection from the gateway to the PBX.

In most cases if using a VPN you may need to open up access on the VPN interface however.

The leg(s) for endpoints outside of the local PBX network will require Ports opening (either 5090 for Apps and SBC connection devices and SIP/RTP ports if using STUN phones).
 
If using ONLY the mobile app and ONLY via tunnel, you need the HTTPS and Tunnel ports open (5001 and 5090 by default).

If using the WebClient and or Web Meeting you will also need the RTP ports
 
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,816
Latest member
natedog