Solved Lockdown 5060

Status
Not open for further replies.

benf

Bronze Partner
Basic Certified
Joined
Sep 27, 2017
Messages
123
Reaction score
12
Hi all, so we have alot of clients connecting to our cloud 3cx systems. However, if I close 5060 to just the SIP vendor, STUN phones wont register once they break the connection.

I had any/5060 and everything is working, I locked it down to our SIP provider to all our 3cx. A phone reboots at a client and the phone doesnt register. I put any/5060 back and it registers. I thought the point of STUN was to not need 5060 open to WAN?

We have alot of clients with an edge vpn which obviously the rule doesnt matter , but we have a few that are coming over STUN or remote employees and so would like to lock this down as much as possible. Am I missing something in the config?
 
Hi all, so we have alot of clients connecting to our cloud 3cx systems. However, if I close 5060 to just the SIP vendor, STUN phones wont register once they break the connection.

I had any/5060 and everything is working, I locked it down to our SIP provider to all our 3cx. A phone reboots at a client and the phone doesnt register. I put any/5060 back and it registers. I thought the point of STUN was to not need 5060 open to WAN?

We have alot of clients with an edge vpn which obviously the rule doesnt matter , but we have a few that are coming over STUN or remote employees and so would like to lock this down as much as possible. Am I missing something in the config?
As an Intermediate Certified, you should know that STUN phones uses the port 5060. STUN simply means that they traverse NAT on the phone side and it also fixes dynamic IP issues. Normally, you would port forward SIP and RTP ports to the phone on the remote site.

The point of the SBC is to lockdown 5060 to your provider's IPs only. The SBC uses port 5090 which can be open to any as it uses a special kind of encryption. If you have more than 2-3 phones, the SBC is the way to go.

If the remote site has a static IP, you can add it to the 5060 allowed sources and they should then register.
 
  • Like
Reactions: AWS2P
As an Intermediate Certified, you should know that STUN phones uses the port 5060. STUN simply means that they traverse NAT on the phone side and it also fixes dynamic IP issues. Normally, you would port forward SIP and RTP ports to the phone on the remote site.

The point of the SBC is to lockdown 5060 to your provider's IPs only. The SBC uses port 5090 which can be open to any as it uses a special kind of encryption. If you have more than 2-3 phones, the SBC is the way to go.

If the remote site has a static IP, you can add it to the 5060 allowed sources and they should then register.

I agree, @benf if you are confused by his statements, perhaps re-review the training materials ;)
 
  • Like
Reactions: Evolute IT
Hi as Frederick said , if sites where Stun is Used have STATIC public IP then add IP adresses to your firewall rule and everything will go fine.
 
  • Like
Reactions: benf and Evolute IT
Hi @benf

If you take a look at our ports document, you will see exactly what 5060 is used for https://www.3cx.com/docs/ports/

In the example you provide, the PBX listens to registrations at 5060 and the STUN phones listens to invites at whatever port you assigned it in provisioning. Blocking 5060 means the traffic from the phone never reaches the PBX and the registration fails.

As suggested above, you could use an SBC with encryption which will use 5090 for SIP and RTP when contacting your PBX.
 
  • Like
  • Wow
Reactions: benf and Evolute IT
Yes you are right we are in the middle of hurricanes here and been running around. I have always had most clients come in over VPN to their own vlan with their single device, and we left 5060 open but wanted to lock it down and just wasnt thinking it through.
 
Hi @benf

If you take a look at our ports document, you will see exactly what 5060 is used for https://www.3cx.com/docs/ports/

In the example you provide, the PBX listens to registrations at 5060 and the STUN phones listens to invites at whatever port you assigned it in provisioning. Blocking 5060 means the traffic from the phone never reaches the PBX and the registration fails.

As suggested above, you could use an SBC with encryption which will use 5090 for SIP and RTP when contacting your PBX.


Yes, thats what we are looking at, and makes more sense for our larger offices, but I just didnt want 5060 open on any. We enabled geo-blocking so I at least set it up for the US to give us some basic protection while we come up with a more thought out plan.
 
  • Like
Reactions: Evolute IT
I think I know what I got mixed up. We have alot of asterisk installs We use Yealinks with the VPN option so 5060 does not need to be open for a remote Yealink phone to connect over WAN from a dynamic IP (someones house for example) . I mixed that up with thinking STUN creates/uses VPN option.

Thanks everyone for indulging my silliness
 
Last edited:
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
111,933
Messages
589,811
Members
164,808
Latest member
jsbjsb