One-way RTP packet loss (2–11 %) from remote extensions

nawy

Premier Customer
Joined
Jul 23, 2025
Messages
4
Reaction score
1
Hello everyone,
I’m experiencing one-way RTP packet loss on a 3CX v20 system running on Prime (Debian-based) behind a FortiGate firewall. The issue affects only remote extensions—they experience 2–20% packet loss in the RTP stream from the extension to the 3CX server.
On the local network, calls work perfectly with almost zero packet loss and very clear audio.
I performed a Wireshark capture, and it confirms one-way RTP loss in the direction from the remote extension to the 3CX PBX. The issue is also reflected in the Call Quality Report in the 3CX event log.
Has anyone encountered a similar issue? Could this be related to the FortiGate firewall configuration, NAT traversal behavior in v20, or something else? Any guidance or recommended troubleshooting steps would be greatly appreciated.
Thank you!
 

Attachments

  • rtp_capture.png
    rtp_capture.png
    246.7 KB · Views: 12
  • 3cx_call_moniter.png
    3cx_call_moniter.png
    80.9 KB · Views: 13
Are all your remote extensions using the 3CX app? Are they on wifi on data?

Does 3CX Firewall test pass?
 
Are all your remote extensions using the 3CX app? Are they on wifi on data?

Does 3CX Firewall test pass?
yes all remote extensions using the 3CX app , only sip ALG failed pass but all is passed .All exts using WiFI
 

Attachments

  • sip alg.jpeg
    sip alg.jpeg
    100 KB · Views: 5
Hello everyone,
I’m experiencing one-way RTP packet loss on a 3CX v20 system running on Prime (Debian-based) behind a FortiGate firewall. The issue affects only remote extensions—they experience 2–20% packet loss in the RTP stream from the extension to the 3CX server.
On the local network, calls work perfectly with almost zero packet loss and very clear audio.
I performed a Wireshark capture, and it confirms one-way RTP loss in the direction from the remote extension to the 3CX PBX. The issue is also reflected in the Call Quality Report in the 3CX event log.
Has anyone encountered a similar issue? Could this be related to the FortiGate firewall configuration, NAT traversal behavior in v20, or something else? Any guidance or recommended troubleshooting steps would be greatly appreciated.
Thank you!
Try to enable, Extension > Option > PBX Deliver Audio , and makesure sipalg and sip inspection on your forti is disabled.
 
Try to enable, Extension > Option > PBX Deliver Audio , and makesure sipalg and sip inspection on your forti is disabled.
I already enabled “PBX Deliver Audio” and I'll configure this on the FortiGate as well.
But I have a question: since the 3CX softphone uses the tunnel on port 5090, how does the firewall affect the packets in this tunnel?
 
It should not, but if it tries to unpack the tunnel traffic for inspection, it might be enough to delay packets.
 
  • Like
Reactions: nawy
Thanks everyone. I’ll configure this on the Forti and then check if it has any effect.
 
  • Like
Reactions: Colby D.

Forum statistics

Threads
111,954
Messages
589,919
Members
164,851
Latest member
DrunkeMeister