Hotdesk cannot login when RTP Encryption (SRTP) is Compulsory (Not Acceptable here error)

Status
Not open for further replies.

Jérôme Wentzel

Premier Customer
Joined
Aug 14, 2019
Messages
31
Reaction score
6
Hello !

When setting up an Hotdesk and configuring the RTP Encryption (SRTP) to Compulsory via the Phone Web admin, users cannot login anymore.
Dialing *77*XXX* = Not Acceptable here error

Of course it is possible to de-activate the SRTP encryption.
But when logged-in user then calls an extension requiring the RTP encryption AND the remote phone being on an network with a bit latency (>2ms), the audio quality is really bad.

I believe that the HD000X accounts are not configured to accept SRTP.
In 3CX's Hotdesk menu, I could not find a way to set TLS mode to required as it is possible to do for the other users (users / Phone Provisioning / 3CX App / Network / RTP Mode / Only Secure).

Any idea how to solve this issue ?
Do we have a way to set the RTP Mode to Only Secure for Hotdesk ?

Many thanks in advance and best regards.
 
Hello,

If you want to use SRTP, I'm afraid hotdesking is not a good option for you.

You will have to use permanent normal extensions (not Hot Desking) or alternatively use the 3CX apps that are encrypted by default with TLS so you won't have to worry about security.
 
Hello John !

Nice to hear from you, ok that is a sad news, I am a bit stuck as this was working quiet well when the latency was < 2ms :(

Would it be possible to:
- "pass" the parameter "account.x.srtp_encryption" during the extension provisioning ?
- Configure a second SIP account / User with SRTP set to Only Secure authorized to SRTP AND login as an other user ?

Many thanks in advance !
 
I'm afraid not, hot desking is not possible with custom templates (which would be needed to do what you want).

I think your only two options are

a) use Hotdesking without SRTP

b) don't use Hotdesking, and have SRTP enabled.

I am a bit stuck as this was working quiet well when the latency was < 2ms
Can you explain what you mean by this? I have not understood what the latency has to do with anything..
 
Me too, but that is the only thing that is different between the hotdesk without the problem and the hotdesk with the problem.

When I manually the configuration on the "remote" hotdesk phones to set the encryption on, all works fine = phone quality is very good. I do not need to do it on the "local" hotdesk.

This problem also occurs ONLY when one of the "remote" hostdesk calls a "remote" phone.

Local = same switch
Remote = switch connected via an L3 service with 2->3ms

If you have any idea I am more than happy to hear it !
 
Keep in mind, phones have adaptive audio buffers that can span hundreds of milliseconds, so 2-3ms is basically nothing to them. They are IP phones, they are designed to cope with network latency by default.

I'm curious, why did you conclude it's the latency rather then the L3 implementation which is a more plausible culprit?
 
Because when I activate the SRTP encryption, all works fine.
I do not understand the reason why it behaves differently. I will X-check the QOS on the L3.
 
Hello John!

It took quiet a long time but we could resolve the issue.
The problem came from the L3 line we rent. in one way the UDP packets were dropped ONLY when packets contained SRTP packets. Crazy.

To overcome the issue, we made a VPN tunnel on top of the L3.

In the various traces we have done, we have seen that the RTP (and SRTP) is going via the server and not sent directly to the phone. Is this a normal behavior of 3CX?
What is the point with the option "PBX delivers Audio in each user extension?

Would it be possible to force direct RTP connection between the phones?
This would improve the security and avoid cases where the server is compromised and somebody listening all conversations.

Many thanks in advance!
 
Hi Jérôme,

I'm glad to hear you figured it out :)


So when you have either of the below being true, then the audio is forced to pass via the server:

- "PBX Delivers Audio" enabled (can be useful for STUN phones, or cases where phones are not on the same network as each other)
- Recordings enabled (the audio goes to the server to be able to make a recording)
- Calls going via the tunnel or 3CX apps (the PBX handles the apps entirely, they cannot work without sending the audio there)
- Calls going via trunk or bridge (because the phone will not be able to directly contact the trunk or the phones across the bridge)

If you remove these factors, the audio becomes point to point.
 
Interesting!

Does this config enable the recording?
View attachment 32302

Because none of the extensions are in the other cases (Calls going via trunk or bridge / Calls going via the tunnel or 3CX apps / PBX Delivers Audio)
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,285
Members
164,662
Latest member
DejanMDS