IP based Trunk issues with SIP port for 3CX is not 5060

Status
Not open for further replies.

VoIPPBX_NZ

Bronze Partner
Advanced Certified
Joined
Sep 10, 2013
Messages
13
Reaction score
10
Hi Guys

We have a 3CX setup with SIP Port 6070, But when we used a Supported Trunk which IP based, it was not working. there are no inbound or outbound calls because when the 3CX is not listening on 5060 and traffic from Trunk provider is sent 5060. Is there any work around for it?

It worked as soon as I put a SIP trunk from another provider which is Account based.
 
Yes the work around is to talk to your provider. With a registration based trunk, 3CX initiates the connection to the provider and provides the port information. With an IP authenticated trunk, the provider expect SIP to be on port 5060. Some providers will let you change that in their portal. Course the real answer is fix whatever is causing you to use a non-standard port.
 
I suppose I should mention that this is theoretical because I don't do silly things like use non-standard ports so I don't have any real world experience in this (as far as with 3CX)
 
This may be a provider restriction as mentioned by @cobaltit

Please speak with your provider, or check their customer portal for the trunk management (if they provide one)
 
Hi John and cobaltit

Thanks for your Feedback, I have checked with Provider, they cannot changed the Port from their end, The issue that they cannot see 5060 open from 3CX side. but Trunks should be effected by changing SIP ports? because I can define ports per Trunk.


@cobaltit, we change 5060 ports for security reasons. we host 100s of 3CX systems and lot of hackers keep on trying from various IPs to hack the systems if left on 5060. Even though the blacklist works fine, but they just use different IP and keep on trying. Hacking attempts are nearly zero with non standard ports and it always worked for us except this recent issues with IP based Trunks

Thanks
Dev
 
And how many 3CX systems were hacked? I think in all my years of doing VoIP I've had one PBX hacked, and that was my fault being lazy and making a test extension and then forgetting to disable/delete it. Since we had reporting in place we picked up the hack in an hour and resolved the issue. Toll fraud is pretty much all those 5060 port scanners are concerned about so follow best practices of strong passwords, restricting international calling and disable remote extensions unless needed. You've reduced your attack surface without causing headaches like this non-standard port usage. And with the 3CX Global Blacklist we see very little in the way of probes now. Best of luck on your quest.
 
We recommend for security reasons to restrict your 5060 port access to the provider only, by using your firewall's ACL. If the traffic is not coming from the provider, it gets rejected and that includes attackers. You can thus install your PBX with 5060 and you should be fine to work with your provider. This is a restriction on their part, but it doesn't mean you can't make it work AND stay secure.

For any remote extensions, either put them behind an SBC, or have them use the webclient and mobile clients. Site to site VPN is also an option for larger deployments. If you have no remote extensions your are already good to go by making good use of your firewall's ACL

https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/ - Slide 22
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,822
Members
164,814
Latest member
Ruben756