Issues with Iphone PUSH after migration to Debian

Status
Not open for further replies.

rdaeseleer

Platinum Partner
Advanced Certified
Joined
Oct 24, 2019
Messages
32
Reaction score
11
Our customer had 3CX installed on Windows Server 2012. Because of this the Iphones did not receive any notifications on the 3CX App.
Yesterday we migrated the 3CX installation to a Debian OS to resolve this issue. We used the latest ISO downloaded from the 3CX website.
The migration went well, but afterwards the Iphones still aren't receiving any PUSH notifications.

The error I receive in my logs is:
Failed to send APNS PUSH to device iPhone8,1iPhone van TKR(Ext.150). Internal exception occured: The SSL connection could not be established, see inner exception.

Version 3CX: 16.0.7.1078
System is up to date according to the updates page.

How can I resolve this issue?
Randy
 
Hi Randy,

The OS and PBX are only part of the equation. The SSL handshake needs to also pass via your firewall, and your ISP box before it goes to Apple.

What you can do now to test this will require some knowledge of how to packet capture on your firewall WAN and LAN interface.

You can call one of the iOS extensions while running the capture, and the PBX will attempt to contact Apple and send the PUSH message (which should fail now).

Then you need to open the captures in Wireshark and see what happens during the handshake.

If you see the LAN side failing, and you see no traffic heading for apple from the WAN side then you can be fairly certain the firewall is blocking you.
 
  • Like
Reactions: rdaeseleer
What firewall are you using and does 3CX pass the firewall test?
 
The firewall test checks out OK on the 3CX. We are now looking into capturing traffic from the firewall to see if it gets blocked by the firewall.
The customer is using Fortinet firewalls.
 
What usually happens (if as suspected) is that the PBX sends tries to establish a TLS connection to the apple servers, and the firewall replies back to the PBX that the connection is reset (rejected basically).

At the same time, the WAN side of the firewall will send absolutely nothing to the Apple servers.

You can look at the DNS request that that PBX performs towards api.push.apple, and see the replies you get. The system will probably use the first IP like so
1607600284714.png
 
  • Like
Reactions: rdaeseleer
I've same problem. Firewall works fine and send packets to Apple server. Also Apple server replies back to the PBX. I think that the problem occurs on TLS Layer.
 
I've same problem. Firewall works fine and send packets to Apple server. Also Apple server replies back to the PBX. I think that the problem occurs on TLS Layer.
Read my last message again because replies back does not mean the message was delivered to Apple.
 
  • Like
Reactions: rdaeseleer
I am looking into firewall captures. Will get back as soon as I got an answer.
 
My firewall also exchanging packets with Apple server. I'm do this on Mikrotik router with packet Sniffer tool.
 
Last edited:
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,990
Messages
590,161
Members
164,925
Latest member
batarong