Solved No audio after AWS v18 - V20 (Sonicwall)

Status
Not open for further replies.

DesertGator

Free User
Joined
Apr 27, 2019
Messages
7
Reaction score
2
Hello - performed an upgrade of an AWS Lightsail v18 to v20. Site uses primary Grandstream GXP2130 - 2170 phones. Under v18 did not use an SBC or router phone. Implemented a Fanvil V65 as a router phone. Can dial outbound and answer calls but no audio. Implemented a 3CX SBC on Windows - same issue. Able to connect GXP's via the Fanvil or SBC and does not resolve issue. Even reset Fanvil, added it as a non-router, connected via SBC and got same issue. Can place calls outbound without issue.

Event logs full of Event ID 12297 "There are no RTP ports available for the media server to establish Call(2)."

Server, firewall & phones all rebooted.

It seems like it must be the Sonicwall TZ 270 firewall (v7) but it was in place before upgrade and no issues with voip. Would seem like with router phone/SBC, firewall would be less of an issue. Checked the somewhat dated Sonicwall 3CX guide & tried to implement but last NAT rule can't be applied due to an error.

SIP provider is flowroute. Supported CODECs are enabled, others removed.

Any ideas as to what I am missing? All phones on correct firmware; firewall on latest maintenance release.
 
Is it passing firewall test?

the troubleshooting needs to be done as the 3CX PBX side as suggested in the error log

This is a local PBX network stack problem. There are like 10k ports available for RTP calls and each call needs 4 ports. If the pbx ran out of ports, there could be a large number of stuck calls.
Stuck calls are caused by improper configuration of Routers and border devices, faulty phones, or a problem in the OS.
Restart 3CX Services
Restart the machine
Restart the firewall / edge device
 
@DesertGator hi there.
Do you run any 3rd party tools on the OS where 3CX is installed?
You could check what service/app use 3CX ports, which 9000-10999 for external calls.
 
Hello & thanks for the response. The 3CX system is running on AWS Lightsail; original install was via the 3CX automated process years ago, with no mods. Simply went in and upgraded from V18 to V20, so not sure how I would run any tools on the OS where 3CX is installed. In addition the the RTP errors showing on dashboard, I get the following errors when running the firewall test:

resolving 'stun-us.3cx.com'... done
resolving 'stun2.3cx.com'... done
resolving 'stun3.3cx.com'... done
resolving 'sip-alg-detector.3cx.com'... done
testing 3CX PhoneSystem 01 SIP Server... failed (How to resolve?)
stopping service... done
detecting SIP ALG... failed (How to resolve?)
testing port 5060... not reachable (How to resolve?)
starting service... done
testing 3CX PhoneSystem Media Server... failed (How to resolve?)
stopping service... done
testing port 5090... not reachable (How to resolve?)
testing ports [9000..9398]... failed (How to resolve?)
testing port 9000... not reachable (How to resolve?)
testing port 9002... not reachable (How to resolve?)

SIP Alg error is not illustrative; Sonicwall don't have this setting. You enable consistent NAT and don't enable transformations. Firewall is configured same as when running v18 successfully. Neither a Fanvil V65 set up as router phone nor using a 3CX SBC resolve the issue. Firewall, phones and 3CX system rebooted multiple times. Seems like the RTP errors are not due to running out of ports but something else like simply being blocked.

What I don't understand is why this v20 upgrade would not longer work with the firewall config that worked with v18. Doesn't adding the SBC or router-phone actually make it easier? There is no mention in the get started docs that there are special requirements to handle in the firewall. As I said, I get what the old sonicwall docs are trying to do, but there is a problem with the last NAT rule they suggest - it can't be saved....and is this even the right path?

Should I try to remove the firewall altogether for testing purposes?

Thanks for any assistance!
 
Your firewall should pass in first place, and not sure how it was working in V18.
Pass the test and take it from there.
 
Well I guess that is the trick for me: How to figure out how to get it to pass.

Note that the 3cx published docs for the required setup for Sonicwall are wrong; besides referring to a much older version of the OS, the last NAT rule it requires is rejected by the Sonicwall with an error.
 
UPDATE: ISSUE RESOLVED!

To clarify: 3CX v20 is in AWS Lightsail (upgrade in place from v18). My Local LAN with users has a configured router phone.

No Sonicwall access or NAT rules needed (only set Consistent Nat to Enabled, and do not enable SIP transformations). No rules were needed in v18 either.

Problem was an overlooked remnant of the AWS Lightsail 3CX instance upsizing - when creating the larger instance to support v20, a new static IP and Lightsail private local IP are created. You detach the old original public IP and reattach it to the new Instance so 3cx maintains the same configured public IP. However, 3CX v20 in the new instance expects to have the original private LAN IP in the cloud that it previously had. I could see that the AWS Instance reported it's LAN IP, and that did not match what was in the 3cx config. All I had to do what click on the alert in the 3cx dashboard alert for this (which was kinda non-obvious as it was next to the public IP and no mention of the local server LAN IP); a popup takes me to the 3cx private IP drop down - I just set it to the correct private IP, and all is working.

Firewall test passes without errors.

Can place calls with no problems and good audio.

Thanks for all your help!
 
Excellent. Thank you for the update and feedback provided here.
For sure, it will be useful for the others!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet