Solved My new remote extension can make calls, but can't receive calls.

Status
Not open for further replies.

Paul Otter

Free User
Advanced Certified
Joined
Jun 5, 2017
Messages
26
Reaction score
3
I'm having trouble configuring my home extension, and I suspect my issue is a routing issue (Client firewall error: Source IP of SIP message is not PBX IP)
My plan is to configure several STUN - Remote extensions, to allow people who don't have VPN devices to work from home.


EXTENSION SETTINGS
My extension has nothing ticked in the Restrictions settings, e.g. Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked).
I have my Home Phone's provisioning method set to "Direct SIP (STUN - remote)"
In Options -> Troubleshooting, I have all 3 tick boxes selected:
PBX Deliveres Audio
Support Re-Invites
Support 'Replaces' header

PHONE HANDSET ( Fanvil X4 with firmware version 2.10.1.6836)
I have updated my phone with the latest configuration file, so it now includes STUN settings.
STUN Server address is [mycompany].3cx.co.uk
STUN Server port is 5060


PBX
I'm using version 16.0.4.493 running on Windows server 2016 hosted in our head office.
I have 99 extensions that are working fine, several of which are connected over two different VPNs, with locations across the globe.
All other extensions are working without issue.
The firewall has passed all tests

The server has 2 NIC's, both of which have internet access but with different fixed IP WAN addresses.

NIC 1 has a WAN address and is used to connect to trunks, as well as for off site Android /iPhone connections.
It has the following ports set to forward all protocols to the PBX
5060-5089
9000-10999
5090
5001


NIC 2 is connected to the business LAN, allowing our Fanvil X4 handsets (Firmware version 2.10.1.6836) to connect, as well as any users on our 2 VPN's

When I first confiugred the PBX I added routing as follows:
route -p add 10.10.0.0 MASK 255.255.0.0 [NIC2's Gateway] <-- This is anything destined for our head office handsets to go our via the LAN
route -p add 192.168.250.0 MASK 255.255.255.0 [NIC2's Gateway] <-- This is anything destined for our home worker VPN connected handsets to our LAN (Which then connects to the internet using another connetion)
route -p add 192.168.51.0 MASK 255.255.255.0 [NIC2's Gateway] <--This is anything destined for our foreign VPN network


route -p add 86.XXX.XXX.125 MASK 255.255.255.0 [NIC1's Gateway] <-- I just added this which is anything destined for my home IP address(I explain why below).


REMOTE ROUTER
At my home, I have my handset in a DMZ, and I've tried enabling and disabling SIP ALG.

I can make calls from my handset, and my BLF's work fine, but I can't receive calls (It doesn't ring).


I downloaded the remote firewall checker:
https://www.3cx.com/docs/firewall-checker-client/

Updated my home router (BT Smart hub) to put my PC in the DMZ instead of my handset.
Disabled my PC's anti-virus software.
Disabled the router's SIP ALG option.

Ran the "Remote Firewall/NAT test utility"
Set the address to be [mycompany].3cx.co.uk:5060

With he STUN Server set to "Use SIP server as STUN", I get the following result:

Trying to resolve address of proxy FQDN:'[mycompany].3cx.co.uk'
Server IP has been resolved: '[NIC 1'S WAN ADDRESS]:5060'->[NIC 1'S WAN ADDRESS]:5060
Start test, v.1.0.4
Extension 3987 is registered
Calling *777
Connection with *777 established
WARN:Source IP of SIP message is not PBX IP: [NIC 1'S WAN ADDRESS]->[NIC 2'S WAN ADDRESS]
Possible causes:
1.SIP ALG or a SIP Proxy has been detected between this computer/network and the target 3CX PhoneSystem. This will cause problems.
Check with the firewall or SIP ALG/Proxy documentation on how to resolve this problem. In most cases SIP ALG should be disabled.
2.Your 3CX PhoneSysem Server might have a Dynamic Public IP address. 3CX PhoneSystem MUST have a Static Public IP.
(A Public IP Address that does not change)
3.You might be using a service like Dyn Dns and the DNS Record has been updated.
Dyn Dns is not supported and you need to configure your DNS correctly if you plan to use 3CX Phone System with an FQDN.
4.3CX PhoneSystem's border firewall might not have the correct Port Forwarding rules configured.
Please launch 3CX Management Console, go to Settings > Network> Firweall Checker> Run Firewall checker.
This will give you an exact list of what ports you would need to open. If the test fails, you would need to login to your firewall and open / port forward the required ports.
Audio port is 10222
Echo call - 601 packets received
WARN:Source IP of SIP message is not PBX IP: [NIC 1'S WAN ADDRESS]->[NIC 2'S WAN ADDRESS]
Possible causes:
1.SIP ALG or a SIP Proxy has been detected between this computer/network and the target 3CX PhoneSystem. This will cause problems.
Check with the firewall or SIP ALG/Proxy documentation on how to resolve this problem. In most cases SIP ALG should be disabled.
2.Your 3CX PhoneSysem Server might have a Dynamic Public IP address. 3CX PhoneSystem MUST have a Static Public IP.
(A Public IP Address that does not change)
3.You might be using a service like Dyn Dns and the DNS Record has been updated.
Dyn Dns is not supported and you need to configure your DNS correctly if you plan to use 3CX Phone System with an FQDN.
4.3CX PhoneSystem's border firewall might not have the correct Port Forwarding rules configured.
Please launch 3CX Management Console, go to Settings > Network> Firweall Checker> Run Firewall checker.
This will give you an exact list of what ports you would need to open. If the test fails, you would need to login to your firewall and open / port forward the required ports.
Audio port is 10222
Calling *888
Connection with *888 established
Answering call from *888
Connection with *888 established
Waiting for Callback from *888
ERROR: Callback test failed. Incoming call from the callback extension has not been received
Possible causes:
1. SIP ALG or a SIP Proxy has been detected between this computer/network and the target 3CX PhoneSystem. This will cause problems.
SIP ALG needs to be disabled or the Proxy needs to be removed/fixed.
Check the firewall's user manual on how to disable any running SIP ALG functionality or contact the firewall's support department.
2. 3CX Phone System might have an incorrect configuration.
Confirm that 3CX Phone System has a public Static IP Address - does not change and Not dynamic - changes.
Confirm that the network interface is correctly configured by accessing the 3CX Management Console > Settings > Network Settings> Stun Server and that the public ip address is correctly entered.
Disable Stun in this case and run the test again.
3. Confirm that you have performed the 3CX Phone System Firewall checker and that the test passes completely.
To do this access the 3CX Management Console and go to General Settings > Firewall Checker > Run Firewall Checker.
4. The firewall of this network from where the 3CX firewall Checker is running is very unreliable and unable to remember port mappings and keep them open.
At this stage it would be best to use 3CX Tunnel, 3CX Session Border Controller or try and switch to TCP Traffic instead of UDP as this will help keep the port mappings open.
ERROR: Callback test - The call has been unexpectedly terminated by PBX
Possible causes:
1. Firewall(NAT) is not working properly with calls addressed to remote devices
2. Network failure
WARN:Source IP of SIP message is not PBX IP: [NIC 1'S WAN ADDRESS]->[NIC 2'S WAN ADDRESS]
Possible causes:
1.SIP ALG or a SIP Proxy has been detected between this computer/network and the target 3CX PhoneSystem. This will cause problems.
Check with the firewall or SIP ALG/Proxy documentation on how to resolve this problem. In most cases SIP ALG should be disabled.
2.Your 3CX PhoneSysem Server might have a Dynamic Public IP address. 3CX PhoneSystem MUST have a Static Public IP.
(A Public IP Address that does not change)
3.You might be using a service like Dyn Dns and the DNS Record has been updated.
Dyn Dns is not supported and you need to configure your DNS correctly if you plan to use 3CX Phone System with an FQDN.
4.3CX PhoneSystem's border firewall might not have the correct Port Forwarding rules configured.
Please launch 3CX Management Console, go to Settings > Network> Firweall Checker> Run Firewall checker.
This will give you an exact list of what ports you would need to open. If the test fails, you would need to login to your firewall and open / port forward the required ports.
Audio port is 10222
Callback - 561 packets received

My current conclusion is that when I have an incoming call, the PBX tries to connect to my home address using its [NIC2] instead of [NIC1].
I'm unsure why it did that though, when I added the extra route :
route -p add 86.XXX.XXX.125 MASK 255.255.255.0 [NIC1's Gateway]


Would the solution just be a catch all route , anything not already specified must go out by NIC1 ?
If so, how do I do that ?

Thank you for reading !

Potski
 
I have now solved this issue.
It was as I suggested related to routing.
The solution was to increase the "metric" on the main WAN facing NIC (I set mine to 2), and it worked immediately.
I no longer need the DMZ on the home router to be enabled, and I also disabled SIP ALG again.

Thanks for everyone that took the time to read my lengthy problem !

Potski
 
Glad to see you were able to resolve your issue and thank you for updating the thread.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,939
Messages
589,843
Members
164,825
Latest member
john.fuchs