Firewall Setup

Status
Not open for further replies.

lodge

Customer
Joined
Jun 21, 2013
Messages
9
Reaction score
1
Since upgrading from v16 (which seemed to go well) users complaining of one way audio on inbound calls. Internal and outbound are fine. Finally figured out that switching off the IVR and making all phones ring in a ring group got round the problem. However user then report that 1 way audio happens when transferring calls, which is presumably why the IVR was broken. Any thoughts?

in the logs:

16/08/2021 16:34:59 - [CM503003]: Call(C:180): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 10.0.96.29:65179
16/08/2021 16:34:57 - Exception: DialogUsage::Exception Can't provide an answer @ ServerInviteSession.cxx:501
 
Last edited:
Hasn't been run since the upgrade (will do so) but as all other call except transferred work fine so surely not a factor ?????
 
Eating humble pie....firewall test show sip alg enabled so something else must have been changed at or around the upgrade. Many thanks for the clear thinking!
 
  • Like
Reactions: AWS2P
Update: the sip alg was caused by the firewall no longer whitelisting the alg test server. Resolved that but still failing full-cone nat. Do we have a full list of servers to allow anywhere?
 
So I would turn off all the rules temporarily to get the green check mark AND to verify that is the issue. Just because the test passes doesn't mean you won't still have issues, aka whitelisting the test servers but your SIP provider is blocked would give a green firewall test and but still have audio issues.
 
  • Like
Reactions: lodge
Also, generally if you have a firewall smart enough to setup ACLs, it should also include logging which will let you know what is being blocked and you can adjust from there.
 
  • Like
Reactions: lodge
Hi @lodge ,

The first thing you need to do is get the Firewall Checker to pass as everyone has mentioned above.

If the issue persists after this, let me know.
 
I have my green tick! I also still have the issue sadly.

since upgrade to v18 internal calls all work fine. external calls work fine but if you transfer then you get 1 way audio. Setting server to do audio does not resolve. Anyone got any bright ideas? Rolling back to v16 is becoming pressing...
 
  • 3CX Version, e.g. Standard Annual 18.0 build 1880
  • Server OS, e.g. Debian 10
  • Is the 3CX Server Hosted and where? on prem linux on hyperv built from 3cx iso
  • IP Phone Make/Model/Firmware yealink various models all latest firmware all same problem
  • Provisioning Method: Local / VPN / STUN / SBC mainly local some manual
  • Trunk Provider or Gateway Make/Model Gamma
  • Has the Firewall Checker passed: YES / NO Yes
  • Are custom Phone Templates being used: YES / NO No
 
If we roll back to v16 what happens to users with the v18 windows app? Do we need to reinstall the old one?

Appreciate any advice.
 
Last edited:
looking through the bug list our experience looks like this

3CX Phone System, Version 18, BETA 2, Build 18.0.0.1865 July 2021​

  • Fixed issue with transfers causing no audio.
  • Fixed recording and renegotiations.
  • Fixed deadlock in Management Console causing error message Server is Busy.
 
Final update in case anyone sees this thread. Rolled back to v16. all working as before. I think v18 isn't quite ready yet! Thanks all for your comments and advice.
 
I don't think it's a v18 issue. We've been using v18 internally since early alpha, and I think we've upgraded around 20 systems to v18 with no audio issues.
 
@lodge If you decide to upgrade again to V18, I wouldn't mind having a closer look at the problem you were facing, now that the Firewall Checker checks out.
 
Hy, I have the exact same error messages since upgrade from v16 to v18
I will run firewall check and post here.
We have no audio issues as far as I can tell.

  • 3CX Version, 18.0.1880 Enterprise Annual
  • Server OS, Debian 10
  • Is the 3CX Server Hosted and where? On Premise
  • IP Phone Make/Model/Firmware 3cx Apps and webclient
  • Provisioning Method: Local / VPN / STUN / SBC
  • Trunk Provider or Gateway Make/Model -
  • Has the Firewall Checker passed: YES on v16, will run it again on v18 in the evening
  • Are custom Phone Templates being used: NO
 
  • Like
Reactions: NickD_3CX
hy
firewall check is OK

1630351423898.png

I see the error after firewall check
08/30/2021 8:57:31 PM - [CM503003]: Call(C:1): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
 
hy
firewall check is OK

View attachment 24092

I see the error after firewall check
08/30/2021 8:57:31 PM - [CM503003]: Call(C:1): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483
Just to be clear, are you having the problem described by the OP?
"....users complaining of one way audio on inbound calls. Internal and outbound are fine. Finally figured out that switching off the IVR and making all phones ring in a ring group got round the problem."

Are you only seeing the message?
 
I see the exact same error message in the log.
I have been told "08/30/2021 8:57:31 PM - [CM503003]: Call(C:1): Call to <sip:[email protected]:0> has failed; Cause: 487 Request Terminated/INVITE from 127.0.0.1:5483" is normal error that can happen from time to time

What does this error message mean?
16/08/2021 16:34:57 - Exception: DialogUsage::Exception Can't provide an answer @ ServerInviteSession.cxx:501

I have no AUDIO Issues on our system.
Since the v18 Update I have been watching the system logs more and was a bit scared because the error is happening often
 
Status
Not open for further replies.

Forum statistics

Threads
111,979
Messages
590,101
Members
164,908
Latest member
FarizQasimov