- Joined
- Jun 6, 2015
- Messages
- 2
- Reaction score
- 0
Hi all,
Since 06 Oct 2026, every web meeting on our PBX fails with MCU Connection Failed (0x0020). It worked until 05 Oct, and nothing was changed on the PBX or the firewall.
Setup: V20 Update 9 (Build 995), PRO, on-premise Windows, Hetzner DC Nuremberg (DE), MCU region Europe, public IP 46.4.220.249 (static, 1:1 NAT).
What we tested:
The upstream (Hetzner) firewall explicitly accepts all inbound traffic to 46.4.220.249, so nothing on our side can drop the reply.
So the MCU pool, across DigitalOcean and Google Cloud, drops only our PBX's source IP. That looks like an IP-level block or blacklist on the WebMeeting/MCU side.
@3CX staff: could someone check whether 46.4.220.249 is blocked on the MCU infrastructure, and lift it or tell us the reason? Happy to provide full pcaps or logs.
Thanks!
Since 06 Oct 2026, every web meeting on our PBX fails with MCU Connection Failed (0x0020). It worked until 05 Oct, and nothing was changed on the PBX or the firewall.
Setup: V20 Update 9 (Build 995), PRO, on-premise Windows, Hetzner DC Nuremberg (DE), MCU region Europe, public IP 46.4.220.249 (static, 1:1 NAT).
What we tested:
- From the PBX, TCP 443 to every MCU currently returned by v18-vc-qos.3cx.net fails (e.g. 159.223.93.4, 35.247.196.146, 34.35.69.212, 34.35.67.34, 34.176.3.76, 157.245.108.209, 188.166.157.144, 167.71.231.53). The SYN goes out, no SYN-ACK ever comes back.
- From 46.4.220.254, a neighbour IP in the same /26 behind the same firewall and upstream, the same MCUs answer immediately (TLS in about 0.2 s).
- From 46.4.220.249 itself, all other HTTPS destinations work normally (8.8.8.8, 1.1.1.1, GitHub…).
- DNS on the PBX is fine, and the license is valid. The dashboard shows the correct static IPv4.
Code:
11:57:04 46.4.220.249.41530 > 159.223.93.4.443: SYN
11:57:05 46.4.220.249.41530 > 159.223.93.4.443: SYN (retransmit)
11:57:07 46.4.220.249.41530 > 159.223.93.4.443: SYN (retransmit, no SYN-ACK)
11:56:51 46.4.220.254.24542 > 159.223.93.4.443: SYN
11:56:51 159.223.93.4.443 > 46.4.220.254.24542: SYN-ACK (after 160 ms)
The upstream (Hetzner) firewall explicitly accepts all inbound traffic to 46.4.220.249, so nothing on our side can drop the reply.
So the MCU pool, across DigitalOcean and Google Cloud, drops only our PBX's source IP. That looks like an IP-level block or blacklist on the WebMeeting/MCU side.
@3CX staff: could someone check whether 46.4.220.249 is blocked on the MCU infrastructure, and lift it or tell us the reason? Happy to provide full pcaps or logs.
Thanks!