Fortigate firewall and SBC

Status
Not open for further replies.

Sangar3

Customer
Joined
Apr 27, 2019
Messages
29
Reaction score
1
3CX in the cloud, and I setup an SBC at home with Yealink T29G. The yealink never shows up on the phones tab so I can assign it an extension. What could this be? Fortigate blocking the SBC?
 
3CX in the cloud, and I setup an SBC at home with Yealink T29G. The yealink never shows up on the phones tab so I can assign it an extension. What could this be? Fortigate blocking the SBC?

This is so helpful... we need to know a bit more about how you are setup...

Cloud-hosted 3CX?
The FortiGate is on which side?
Is the SBC correctly configured and working?
 
This is so helpful... we need to know a bit more about how you are setup...

Cloud-hosted 3CX?
The FortiGate is on which side?
Is the SBC correctly configured and working?

Oops sorry.
Cloud-hosted 3CX on Azure, yes.
Fortigate on my end, behind a cablemodem.
How do I verify SBC is working properly?

I just setup another system azure, but this time no Fortinet, just a simple linksys router with no issues.
 
Also, if I provision the phone manually, it works fine, but I wanted to ensure I can set this up with the ability to have it show up automatically, so I can assign an extension vs having to manually configure each phone on the phone web admin
 
Oops sorry.
Cloud-hosted 3CX on Azure, yes.
Fortigate on my end, behind a cablemodem.
How do I verify SBC is working properly?

I just setup another system azure, but this time no Fortinet, just a simple linksys router with no issues.

You might wanna check in your FortiGate config if UPnP/PnP is enabled for your Voice VLAN (if any) or simply for your network.

Also, to check if the SBC is working, you can run "service 3cxsbc status" and see if it's running or if it gave an error.
 
You might wanna check in your FortiGate config if UPnP/PnP is enabled for your Voice VLAN (if any) or simply for your network.

Also, to check if the SBC is working, you can run "service 3cxsbc status" and see if it's running or if it gave an error.


I ran that command, so looks like it is running

● 3cxsbc.service - 3CX Session Border Controller
Loaded: loaded (/lib/systemd/system/3cxsbc.service; enabled; vendor preset: enabled)
Active: active (running) since Sat 2019-05-04 17:31:32 BST; 1h 37min ago
Main PID: 1166 (3cxsbc)
CGroup: /system.slice/3cxsbc.service
└─1166 /usr/sbin/3cxsbc /etc/3cxsbc.conf

May 04 19:09:13 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/security.cpp:915 | TLS(state=3) reading, qsize=0
May 04 19:09:13 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/security.cpp:1342 | Keep-alive received
May 04 19:09:13 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/security.cpp:872 | TLS: written 8 out of 8 bytes
May 04 19:09:13 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/TunnelTcp.cpp:765 | Sending keep-alive. Stats: KA sent: 3396, KA recv: 792
May 04 19:09:14 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/security.cpp:872 | TLS: written 8 out of 8 bytes
May 04 19:09:14 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/TunnelTcp.cpp:765 | Sending keep-alive. Stats: KA sent: 3397, KA recv: 792
May 04 19:09:15 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/security.cpp:872 | TLS: written 8 out of 8 bytes
May 04 19:09:15 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/TunnelTcp.cpp:765 | Sending keep-alive. Stats: KA sent: 3398, KA recv: 792
May 04 19:09:16 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/security.cpp:872 | TLS: written 8 out of 8 bytes
May 04 19:09:16 raspberrypi 3CXTunnel[1166]: TUNL | 1980805120 | /home/repomaster/workspace/SBC/Sources/Projects/3CXSBC/TunnelTcp.cpp:765 | Sending keep-alive. Stats: KA sent: 3399, KA recv: 792
pi@raspberrypi:~ $






I have one VLAN setup, with all my devices, including the Yealink T29G and the SBC.
 
The phone says updated skipped. I ran verbose log on 3cx server and did not see anything there.
 
The phone says updated skipped. I ran verbose log on 3cx server and did not see anything there.

Can you screenshot your FortiGate UI please? As I am seeing there, the SBC is working properly so it might have something to do with your firewall blocking PnP.

Also, when you say that manually configured it works, is that configured in SBC mode or STUN?
 
Can you screenshot your FortiGate UI please? As I am seeing there, the SBC is working properly so it might have something to do with your firewall blocking PnP.

Also, when you say that manually configured it works, is that configured in SBC mode or STUN?

Which UI screen do you want to see? I manually configured the phone by going to the admin of the phone and setting it to connect directly with the cloud 3cx server. I don't believe that was stun mode?
 
I just reset the phone, went into 3cx, added the phone to my extension manually, took the provision url and put it on the server URL under autoprovision. It restarted, and now I have service.

Under phones, it shows my phone and it shows going through the SBC.
 
  • Like
Reactions: Evolute IT
I just reset the phone, went into 3cx, added the phone to my extension manually, took the provision url and put it on the server URL under autoprovision. It restarted, and now I have service.

Under phones, it shows my phone and it shows going through the SBC.

Look through the UI for the Fortigate and see if you can spot something about PnP. Other than that, you can always do what you just did and yes it will work.

When connected directly to 3CX Cloud, it is essentially Direct SIP (STUN).
 
Look through the UI for the Fortigate and see if you can spot something about PnP. Other than that, you can always do what you just did and yes it will work.

When connected directly to 3CX Cloud, it is essentially Direct SIP (STUN).
This is stun even though it is showing as SBC?

I am going to take a look at the Fortinet in more detail, I may have to open a case with them.
 
So unless the Fortinet is a switch there shouldn't be anything it does to affect this. The SBC initiates the connection outbound to 3CX so no port forwarding is needed. uPNP doesn't matter as we don't care about traffic passing through the Fortinet. If the switch is blocking multicast that would cause the situation you describe. You'd also want to make sure the 29G is on the supported/current firmware:

https://www.3cx.com/docs/plug-and-play-ip-phone/
 
So unless the Fortinet is a switch there shouldn't be anything it does to affect this. The SBC initiates the connection outbound to 3CX so no port forwarding is needed. uPNP doesn't matter as we don't care about traffic passing through the Fortinet. If the switch is blocking multicast that would cause the situation you describe. You'd also want to make sure the 29G is on the supported/current firmware:

https://www.3cx.com/docs/plug-and-play-ip-phone/

This is a fortinet 60E firewall. It is on the same subnet as the phone. I was making calls on it an hour ago, after I provisioned it manually by going throiugh the phone admin page, and it showed SBC on the 3cx phones tab. Now, it shows no service.. gah.

T29 is on latest. the yealink page showed .50 but then 3cx had .60
 
Status
Not open for further replies.

Forum statistics

Threads
111,924
Messages
589,754
Members
164,796
Latest member
Dame24