• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

Generic SIP Trunk with TLS1.2

Status
Not open for further replies.

mbashar89

Customer
Basic Certified
Joined
Mar 8, 2021
Messages
11
Reaction score
0
Dears,
i am trying to establish Generic SIP trunking with TLS between 3CX and Aethra SBC .
Steps I did on 3cx :
1- under SIP trunking Option tab i select TLS and upload CA certificate.
2- Security---> secure SIP , I paste Public certificate and private key.

My question :
1- Are Steps I did above correct ?
2- When i capture traffic between 3CX and SBC there is no any exchange for public certificate , why?
3- in this case 3CX work as client or server ? i mean who should start exchanging the certificate?


thanks in advanced
 
You mentioned you uploaded a certificate and private key under the Secure SIP/TLS” setting of the PBX, which certificate did you enter here, as this is usually set to the PBX Nginx certificate and not just the root certificate for the provider, are you using a custom FQDN for PBX? as this section already populated with the PBX certificate when using a 3cx FQDN. If custom FQDN and not a wildcard certificate (sip TLS requires a certificate for the full FQDN), then this needs to contain a full certificate chain with the certificate for the PBX FQDN, intermediate and root certificate for the CA.

Did you also check that the provider supports TLS with their SBC? As when using a local SBC traffic is usually via an internal IP address which is not something that certificates will work with, certificates work with FQDNs and work only with registration-based providers, is the certificate that you upload under the sip trunk settings the root certificate given to you by your provider?

Check this guide for the full description of requirements and how this should be configured and also how to troubleshoot: https://www.3cx.com/docs/sip-trunk-tls-srtp/
 
Hello ClsVip,
The scenario is provider - - - - - - SBC----3CX

I already have tls connetion between sbc and provider. Provider give me CA certificate and two public certificate and private keys for SBC and pbx.
As I said connection between provider and sbc working with tls. I I want also connection between sbc and 3cx to be tls.


So where I can use the three certificate ( CA- PUBLIC CERT - FOR Private key) I got from provider at 3cx
 
Where does the VoIP provider require them to be?
 
Please read this before going any further: https://www.3cx.com/docs/sip-trunk-tls-srtp/

In your scenario 3CX is the client so it needs to verify the certificate the SBC is sending using the root certificate the provider used to sign the SBCs hostname.
 
Status
Not open for further replies.

Forum statistics

Threads
112,148
Messages
590,962
Members
165,168
Latest member
Stephan Eusebe