Outbound Firewall Rules/SIP Registration

Status
Not open for further replies.

nick.fletcher

Forum User
Joined
Jul 23, 2019
Messages
7
Reaction score
0
So some of this is probably my own ignorance with SIP traffic, and the required configuration.

We have a 3CX phone server sitting behind a WatchGuard router. Everything works great. We just got a backup WAN connection. WatchGuard has a feature that they call SD-WAN, but really what it does is look at loss, jitter, and latency and will failover to a different connection based on this criteria. This works well for Outbound connections. We use user based authentication for our SIP lines, which I thought meant the SIP lines would reach out to register.

My goal was to setup a firewall rule that would grab all necessary outbound traffic and failover to the backup WAN connection if the specified criteria reached a certain threshold.

I went into the traffic logs on the router and started to look into outbound traffic from the 3CX server and was seeing some very weird results. I understand that is not 3CX specific, and I am not looking for help with that...

What I am trying to determine is what exactly needs to be open outbound? What needs to be open to reach out to the SIP trunk provider? When a SIP trunk is refreshed, is that all traffic that originates on the 3CX server going outbound?

Some of this is likely my ignorance of the process of how SIP trunks register and how that traffic is handled. Can you help me fill in the gaps?
 
Not sure how Watchguard is doing it but if it's just fancy load-balancing that can be a problem. We use another product that keeps the same public IP regardless of the connection that works. But if it's just bouncing the SIP traffic back and forth that's likely going to be an issue. You might get away with it if you can do IP authentication and put both WAN IPs in there.

As far as what you are asking for, the SIP registration is initiated from 3CX out to your provider but is two-way after that. Watchguard support should be able to clarify whether they expect SIP to work with their SDWAN feature
 
Not sure how Watchguard is doing it but if it's just fancy load-balancing that can be a problem. We use another product that keeps the same public IP regardless of the connection that works. But if it's just bouncing the SIP traffic back and forth that's likely going to be an issue. You might get away with it if you can do IP authentication and put both WAN IPs in there.

As far as what you are asking for, the SIP registration is initiated from 3CX out to your provider but is two-way after that. Watchguard support should be able to clarify whether they expect SIP to work with their SDWAN feature

It should do a true failover where the public is changed. Well, we do outbound NAT to a different public which is a whole different issue I need to figure out because it will never work on failover...

So the SIP registration reaches out from 3CX but then is 2 way. Do you know, will the responses back from the SIP provide always be replies to the original registration (AKA: established traffic) or will it be new inbound traffic originating from the SIP provider?
 
Hi nick

These are the default ports https://www.3cx.com/docs/ports/

However, the provider might use a different range when setting up a call audio stream.

A registration based provider means you initiate the registration process, they reply back and a session is established. There will be period updates to refresh the registration, or incoming traffic when they send you an invite for an incoming call. When this happens the provider will tell you what IP and port they wish you to send the audio.

From what I understood you wish to switch to other WAN interfaces and hence a different public IP for internet access failover?
 
Hi nick

These are the default ports https://www.3cx.com/docs/ports/

However, the provider might use a different range when setting up a call audio stream.

A registration based provider means you initiate the registration process, they reply back and a session is established. There will be period updates to refresh the registration, or incoming traffic when they send you an invite for an incoming call. When this happens the provider will tell you what IP and port they wish you to send the audio.

From what I understood you wish to switch to other WAN interfaces and hence a different public IP for internet access failover?

You are correct, but the real hurdle is trying to do outbound filtering. I need to allow only to outbound ports necessary, so I can apply failover policies correctly. I have the inbound ports set you linked to. Those have been working for a long time and I found that article previously. Unfortunately, it doesn't specify outbound ports that are necessary.
 
It doesn't specify what outbound ports are necessary because 3CX doesn't control that, your provider does. During the negotiation 3CX tells the provider to talk to me on this port (something between 9000-10999) and the provider says ok talk to me on this port. You need to find out from your provider what range that is.
 
Exactly, as @cobaltit pointed out, you will receive audio at the 3CX defined ports, but the provider will tell you what port to send them audio to. The PBX accepts and sends audio there as per the provider's request (hence needing access to those ports for outbound traffic)

So when a call is set up the the following conversation takes place (described simply):

3CX: Hello provider, I wish to call number xxxyyy and I will listen for inbound audio on port 9000

Provider: Hello PBX, please send me your outbound audio on my port 15031, and I will send you your inbound audio at your port 9000


Your provider can tell you their range so you can set up your outbound policy accordingly
 
  • Like
Reactions: nick.fletcher
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,932
Messages
589,807
Members
164,805
Latest member
Diana Paladutsa