Port Forwarding

Status
Not open for further replies.

vrheartland

Forum User
Basic Certified
Joined
Sep 21, 2018
Messages
16
Reaction score
0
After the recent system upgrade, we have lost audio (both ways) on our phones - though they are registering correctly... Ran the firewall checker and found the new ports 10600..10998 are failing the full cone test...

Question is what is the best practice to resolving this? We have two phones, behind a firewall, sharing a single public IP on a firewall running pfSense...

Most of the troubleshooting guides I have seen address port forwarding from the perspective of us having our own 3CX system on premise. Our lines are with 3CX cloud...

Any inputs appreciated!

Thanks!

-vrheartland
 
You just need to extend the ports used before 15.5 SP6 to now use 9000-10999 udp on your firewall setup - https://www.3cx.com/community/threads/3cx-phone-system-audio-ports-increased.60235/

Rerun the firewall check.

How are the phones provisioned - SBC or Stun. If stun you may need to have separate ports for each phone and setup port forwarding/

You could also tick 'PBX Delivers Audio; under the option tab for extension

If the above does not work look at https://www.3cx.com/community/threa...etgear-nighthawk-x4s-d7800.54620/#post-225296
 
Maybe I am looking at it the wrong way... Not surprising :)

Since we do not have a 3CX onsite (all STUN) we don’t have a 3CX server for the NAT translation

Do we need to create separate NAT rules for each individual phone/device? Seems like a lot of overhead, but if that’s needed, I can do that... Would assume NAT rules would be setup for each phones ID address?
 
You have a 3cx server somewhere. The RTP ports need to be updated on whatever firewall is in place - even if it's just the Linux iptables. Start there. Then rerun the Firewall Test.
Then if problems continue, we can address them.
 
  • Like
Reactions: YiannisH_3CX
Hello @vrheartland

Please note that the port increase affects the 3CX server side. Even if the server is not on premise you need to allow the extra ports on the firewall in front of the PBX. If your PBX is hosted on OVH you will need to add the extra ports to the Debian IP tables. Run the firewall checker to confirm that all ports pass.
 
Ok so this is making more sense - now the catch :)

We are on a 1 year free license from 3CX - pretty happy so far - but as such - our PBX is fully hosted by 3CX - I am not sure where that is hosted, whether we have access to that platform either...

-vrheartland
 
Is this also hosted by 3CX? If so then the ports are already open. Go to management console / Settings and check if you have a parameters tab. Is it there?
 
Appears to be? I do have a Settings/Parameters tab - anything specific to look at?
 
I do have a Settings/Parameters tab - anything specific to look at?
This means that the instance is not hosted by 3CX and that it is hosted in an instance you control. On 3CX hosted instances the Parameters tab in not available.
You will need to gain access to the instance and adjust your IP tables in order for the Firewall checker to pass and to resolve your issue.
 
  • Like
Reactions: craigreilly
Status
Not open for further replies.

Forum statistics

Threads
111,900
Messages
589,629
Members
164,765
Latest member
domi