IP address (or country) to whitelist for SSL renewals

Status
Not open for further replies.

techexperts33

Bronze Partner
Basic Certified
Joined
Nov 13, 2013
Messages
14
Reaction score
10
Hi, we recently implemented geo-filtering on all of our client's firewalls. Now, the SSL renewal process has started failing. I'm assuming it is because the on-premises servers can't reach the SSL renewal server. I've reviewed the logs on the firewalls several times, and can't find where the phone system is reaching out for the renewal.

Could anyone tell me either the IPs used for the cert renewals, or the country, so I can whitelist them?

Thank you.
 
Could you please first give the following a try, access the Management Console, go to "Settings >> License" and click on "Refresh License Key Information". Do you get any errors when you do that?
 
Thanks Chris - I get this:
3CX failed to establish a TCP connection to activation.3cx.com.
Ensure that the local or border firewalls are configured to allow outbound traffic to activation.3cx.com
I checked that host and it is located in the United Kingdom - I've whitelisted that country and will check to see if the SSL renews today.
 
  • Like
Reactions: ChrisC_3CX
Great! Do let us know how that goes!
 
Could anyone tell me either the IPs used for the cert renewals, or the country, so I can whitelist them?
This is for the Let's Encrypt cert? They don't publish a list and change IPs frequently. I suspect they validate from multiple locations but haven't really dug into that, that may just be renewals from different servers over time. When I poked at this once for a web server project, I want to say there was a connection from China and/or Russia, I forget which, but I recall having to open up a bunch of locations for the cert.
 
This is for the Let's Encrypt cert? They don't publish a list and change IPs frequently. I suspect they validate from multiple locations but haven't really dug into that, that may just be renewals from different servers over time. When I poked at this once for a web server project, I want to say there was a connection from China and/or Russia, I forget which, but I recall having to open up a bunch of locations for the cert.
For the activation server that also handles the certificate renewals, the IPs don't change often.
Also to my knowledge, never have these servers been hosted in China or under a Chinese IP.

You may have confused this with traffic from your downloads server that is a CDN and there, indeed you can see traffic coming from different IPs.
 
  • Like
Reactions: ChrisC_3CX
For the activation server that also handles the certificate renewals, the IPs don't change often.
Also to my knowledge, never have these servers been hosted in China or under a Chinese IP.

You may have confused this with traffic from your downloads server that is a CDN and there, indeed you can see traffic coming from different IPs.
I was talking about raw/generic Let's Encrypt renewals. Does 3CX do those and then transfer the cert to the 3CX server? I assumed they were being done on the 3CX server, but maybe it's DNS validation? If so disregard what I said. :)
 
I was talking about raw/generic Let's Encrypt renewals. Does 3CX do those and then transfer the cert to the 3CX server? I assumed they were being done on the 3CX server, but maybe it's DNS validation? If so disregard what I said. :)
Yes, 3CX does those on behalf of each PBX and transfers the certificate to the 3CX Server. :)
 
Status
Not open for further replies.

Forum statistics

Threads
111,982
Messages
590,121
Members
164,909
Latest member
Jacob.Ive