Solved Outbound Rules for Forwarded Calls

Status
Not open for further replies.

chris.pallett

Customer
Intermediate Cert.
Joined
Apr 10, 2020
Messages
5
Reaction score
1
Hi there,

This isn't a new issue but I cannot see any posts where this has been resolved...

The scenario is that a call comes into the system and a rule forwards it out to an external number. The forward fails with the message "target endpoint cannot be built" because there is no matching rule for the external number. The rules we do have limit calls based upon group and because it is a forwarded call, it does not originate from a group and does not match the existing rules.

The only way I can make it work is a either a strict outbound rule based on the external number or a loose outbound rule to allow anything, which negates the security of the group based rules. The external number might change 2-3 times a day and it's not practical to have the client give us a list of possible numbers they might wish to forward to.

Has anybody come up with a way to allow the forwarded calls without compromising the whole security of the system?

Thanks in advance.
 
It sounds to be a user issue. When someone programmes in the forwarding destination they are expected to use a number format that is valid for that PBX. This means that they must include an outbound prefix if used. The number must match how calls would normally be dialled from that extension. Not really asking a great deal, simply, that they pay attention. Perhaps a "reminder" training session is in order. Outbound rules can only compensate for so much.
 
Sorry, I see now what you are saying.

The rules we do have limit calls based upon group and because it is a forwarded call, it does not originate from a group and does not match the existing rules.

That logic, does not make sense to me. If a call is forwarded, from an extension, that is part of a group, then the outbound rules, that apply to members of that group, should apply to the forwarded call. Why would they not? If the extension is to be prohibited, from forwarding to an outside number, then that should be a separate extension option, like a tick box.
 
Last edited:
If a call is forwarded, from an extension, that is part of a group, then the outbound rules, that apply to members of that group, should apply to the forwarded call.
I agree with you completely, that is the behaviour that I was expecting to see.

Also should point out that the forward is configured on the handset so it is a SIP 302 redirect rather than a forward from any of the 3CX apps. It is a shared handset so forwarding via the handset is the only way to give the client the flexibility they need.
 
configured on the handset so it is a SIP 302 redirect
that's surely why it doesn't work, as it is not supported on 3cx side and on sip provider side too perhaps.
So this is probably not a rule problem but the way you engage forwarding.
 
Many set options do not "play nice" with 3CX and are best avoided, as they can have unintended consequences, as you've discovered. For those, with less restrictive outbound rules, this might not be an issue.
 
that's surely why it doesn't work, as it is not supported on 3cx side and on sip provider side too perhaps.
So this is probably not a rule problem but the way you engage forwarding.
Do you have any ideas how to do what we're trying to do in a way that is supported?
 
Hi @chris.pallett

The only way I can make it work is a either a strict outbound rule based on the external number or a loose outbound rule to allow anything, which negates the security of the group based rules. The external number might change 2-3 times a day and it's not practical to have the client give us a list of possible numbers they might wish to forward to.

Has anybody come up with a way to allow the forwarded calls without compromising the whole security of the system?
There is another way to do this using the outbound rules without compromising the security of the system.
All you need is an additional outbound rules to block users from directly dialling those numbers.
1586768557059.png
This examples assumes that there are 2 groups in your environment each with its own outbound rule with any restrictions you might have in place for each group. Those will remain unchanged.
Below the 2 rules there is a security rule has BLOCK selected for all routes and includes both groups. So if a member of either group makes a call that does not match the first 2 rules it will hit the third rule which will not allow the outbound call.
Then you will need a forth rule that allows the system to forward calls as the system is not part of any group and it is the system that forwards the calls in your setup.

The above is just an example. You can adjust it to your needs and test it.
 
  • Like
Reactions: chris.pallett
  • Like
Reactions: JohnS_3CX
  • Like
Reactions: chris.pallett
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,943
Messages
589,861
Members
164,834
Latest member
Edal