Phone Utility Buttons Across a VPN

Status
Not open for further replies.

contoured

Gold Partner
Advanced Certified
Joined
Sep 7, 2016
Messages
117
Reaction score
10
Hello - It has come to my attention that the utility buttons (Firmware, Reboot, and Reprovision) on the Phones page do not work for handsets connected via VPN.

The configuration consists of 3CX (v16 update 3) hosted in GCP. It has 4 remote offices, 3 of which use a SBC. The 4th is much lager with nearly 100 phones so we utilize an IPSec VPN between the office and GCP. Inbound, outbound, internal calls work as expected for all 4 sites. However, while the utility buttons work fine for the phones attached via SBC, they do not work whatsoever for the phones attached via VPN. When you select a phone from that site then hit one of the buttons absolutely nothing happens. I should mention that the site in question consists of Yealink and Htek phones.

Any suggestions? Can anyone provide information on how the utility button mechanisms work? I've done some searching but have yet to find anything useful.
 
(Firmware, Reboot, and Reprovision) on the Phones page do not work for handsets connected via VPN.

90% of our sites are on VPN connection and as far as I am aware we have no issues with these settings and we use Yealinks.

What I would say is please describe how your VPN is configured, we use software Pfsense from a cloud platform down to the local site firewall. What we do have to do however is allow all on the VPN interface attached to the firewall.

These settings are send also using HTTP/S so I would run a Wireshark and see what is going on. How have you provisioned the phones ? Option 66 or manually via provisioning link ?
 
  • Like
Reactions: contoured
Hello eddv123 thank you for the response. I'm also using PFsense for this site. I had a bit of trouble getting the IPsec to connect to GCP but once we finally did it's been stable for months. I did not think that could be the problem. I'll verify but I'm positive I have an allow all rule for the VPN interface as well. Would you be willing to share the IPsec settings you use for you PFsense?

As for provisioning, we are using option 66.
 
What I would say is please describe how your VPN is configured, we use software Pfsense from a cloud platform down to the local site firewall. What we do have to do however is allow all on the VPN interface attached to the firewall.

Here are my IPsec settings

Phase 1
Authentication Method: Mutual PSK
Negotiation Mode: Main
My identifier: My IP address
Peer identifier: Peer IP
Encryption Algo: 3DES
Hash: MD5
Lifetime 36000
Margintime: 60
NAT Traversal: Auto
DPD: enabled
Delay: 10
Max failures: 5

Phase 2
Mode: Tunnel IPv4
NAT/BINAT: None
Protocol: ESP
Encryption Algo: AES128-GCM
Hash Algo: SHA1
PFS Key Group: 16
Lifetime: 10800

In Firewall > Rules I have a rule that allow any from GCP LAN > Local LAN. There is also an IPsec rule that allows any any.
 
These settings are send also using HTTP/S so I would run a Wireshark and see what is going on. How have you provisioned the phones ? Option 66 or manually via provisioning link ?

The commands are sent via SIP, not HTTP/HTTPS no?
 
all those commands are send via SIP to the phone, same as an INVITE but in this case it is NOTIFY
 
all those commands are send via SIP to the phone, same as an INVITE but in this case it is NOTIFY

Apologies, yes I have confused everyone, I mean the HTTP provisioning process, yes you are right a SIP NOTIFY is sent from the PBX.

In a VPN/DHCP provisioning setup/option 66 an HTTP GET request is sent LAN >> LAN to 3CX which will respond with an HTTP/XML file (HTTP 200 OK).

Regardless, as long as it does not effect any security restrictions, allow all traffic between your VPN interfaces or restrict via IP.
 

Attachments

  • option66prov.jpg
    option66prov.jpg
    158.7 KB · Views: 6
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,818
Members
164,810
Latest member
astrobalaji