Phones behind nat needs portforward on router

Status
Not open for further replies.

Leif Neland

Joined
Sep 6, 2018
Messages
3
Reaction score
0
I'm trying to run 3cx on a server in our hosting center, and the phones in branches behind nat routers.
Were using various (older) cisco/linksys phones.

It seems this issue is still not fixed.

https://www.3cx.com/community/threads/hosted-3cx-testing-remote-extensions-wont-auth.29506/

If I enable portforwarding in the router, so for instance external 5063 goes to internal 5063 on a phone it works.

If I don't,a phone with internal port 5063 have external port 12345, it tries to register, but 3cx answers back on port 5063, so the phone never gets the reply.

It is almost managable, but it requires I give all phones a fixed local ip, different ports and makes a portforward for each phone.

This shouldn't be needed; It wasn't needed on an asterisk server, neither on my home SPA525G, which have 5 lines, connected to 4 different accounts on 3 different voip-providers.

I haven't used provisioning the phone, as I don't want to loose the lines to my other voip-providers.
 
The issue is that the NAT is not one-to-one. Based upon your description, the router is changing the source port when it traverses the WAN.

There is a setting in Settings, Network, Firewall by which you can have 3CX alter how it responds to a REGISTER. This essentially tells 3CX to ignore the message contents.

As the post that you referred to does not mention the make of router nor other details, it is not clear that the root cause is the same.

Regardless, not knowing more of the situation, you may still run into some issues. Ideally, the NAT would be one-to-one so that the information contained in the SIP headers would match that which is physically seen at the devices. A SIP ALG or helper of some sort may be in play which if so, should be disabled.


The router has to maintain a set of NAT and PAT tables. I had a site which was remote and running and older ASA of which I had no access. It would handle 5 phones behind the NAT before it had issues. Once I got to a 6th, it could no longer manage the configuration.

A site-to-site VPN would avert the issue as might port forwarding or an SBC. If you unable to implement any of these, then you need to have each phone set such that ITS local SIP port and local RTP ports are different than the others and you will need to have keep-alives enabled or use STUN. These will try and keep ports open on the router as well as try and provide a unique message for each phone in an attempt to help the router maintain the paths.
 
  • Like
Reactions: craigreilly
I would strongly recommend using a 3CX SBC for sites with more than one or two sets. The Raspberry Pi model is inexpensive, and avoids having to troubleshoot, try to configure,or replace a router. It also keeps all set to set calls (voice data), within the local network, thus reducing bandwidth back to the PBX, if that is a concern.
 
Strange. I found the option "Send Media to IP and port of REGISTER"
I clicked it on, and phone registered.'
To make sure that was the reason, I clicked it off; phone didn't register.
I clicked it on; now phone doesn't register?!?

With tcpdump on the outside of the pfsense router/firewall, I see 3CX still sends to the portnumber 5062, not the port firewall translates outging pkt's to the 3CX

The router is pfsense,
As I said; I could do portforwarding in pfsense, but I rather avoid it.
 
Well, clicking on and off may or may not be an issue.

If the phone registered, then it received an expiry time which meant that no further communication to the server was expected before that time. Not knowing more than what has been indicated, I am uncertain without seeing a pcap file during the period that the events took place as to what occurred and how the messaging is being handled.

While I understand the desire, I still feel that the reliability is not as robust as you will need.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,894
Messages
589,601
Members
164,763
Latest member
Techmansam