How to Configure Secure SIP TLS

Status
Not open for further replies.

comfident

Bronze Partner
Joined
Oct 22, 2015
Messages
36
Reaction score
1
For the time being there is no "how to" for V15.5 SP4 or higher. We plan on allowing SIP TLS as a provisioning option at some point.

For now, assuming you are using a 3CX FQDN, and the LEt's Encrypt Cert, all you need to do is log into each phones interface, switch the transport to TLS and the sever SIP Port to 5061.
You may have to disable also automatic reprovisioning on the phone in case it switches back to the defaults.
 
  • Like
Reactions: complex1
I am trying to configure the 3CX Client for a Android smartphone for first step.
First i generated a RSA key and configured it within options/security/Secure SIP.
When i change within an extension the 3CX Client setting SIP-Transport from UDP to TLS, the connection does fail. I also tried reprovision, resend welcome mail and import on the smartphone the config with QR code again.

Does the certificate common name must be the same as the 3CX FQDN, or is any certificate just fine?
Does the 3CX Client must have the private CA certificate installed on the smartphone which the 3CX certificate was signed from?
Where do i have to change the SIP Port to 5061 and does this affect also other phones or devices?
 
As I implied, we are still working towards the full implementation of SIP TLS the way we want it, which will include also provisioning options for the 3CX mobile apps as well.

Nonetheless, if you want to check out SIP TLS for the Android client, I would first suggest you sign up for the beta: https://play.google.com/apps/testing/com.tcx.sipphone14
There have been quite a few improvements towards this direction.

Onto to your question, I believe that, at least currently, SIP TLS is only possible when connecting externally using the 3CX FQDN. When the internal IP is used it does not work.

I quickly tested it just now on an Android (using Beta) and all I needed to do is:
  • Copy the External PBX IP to the Internal PBX IP (so that it connects externally always)
  • Change SIP Port to 5061
  • Disable the Tunnel
  • Switch Transport to TLS
 
I only want to open Ports 506(0|1) for the SIP trunk providers IP andresses and don't want to disable the tunnel.

Do you plan that SIP TLS work through the 3CX tunnel for 3CX clients and external phones?
 
SIP TLS and Tunnel is technically not possible to work together. The tunneling service would act as a "man-in-the-middle" which wouldn't work. Encrypted Tunnel like the SBC currently has is not implemented yet for mobile clients.
 
Status
Not open for further replies.

Forum statistics

Threads
111,896
Messages
589,608
Members
164,764
Latest member
billza209