• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha Learn more

Port number for STUN-remote phone

Status
Not open for further replies.

Foiler

Free User
Joined
Jul 31, 2020
Messages
47
Reaction score
6
When I provision a new Fanvil X3U phone for STUN-remote the Local SIP port of phone in the Provisioning tab of the extension shows as 5065.

However, on logging into the phone itself, the port setting in the Line-SIP page shows as 5060, but it also shows as registered.

Given the above anomaly, I just wanted to clarify the correct port setting for STUN-remote phones .. it is reportedly 5065 for the first remote phone, and incremented for subsequent remote phones .. is that correct?
 
https://www.3cx.com/blog/voip-howto/stun-voip-1/

  • Phase1: Computer A sends a STUN request through gateway 192.168.1.1 to STUN server outside the network, listening on 64.25.58.65 using source port 5060.
  • Phase2: The gateway (192.168.1.1) forwards the request to STUN server (64.25.58.65) and changes port 5060 to port 15060.
  • Phase3: The STUN Server (64.25.58.65) sends a response back to Computer A through the gateway with public IP 212.128.56.125 specifying that the request was received from IP 212.128.56.125 and port 15060
Source port will change based on local SIP port which will have been provisioned when the phone has pulled its config from 3CX. Check that you're not looking at the SIP server details which will be accepting SIP on 5060. Somewhere on the fanvil it will have that specified unless you registered the phone first then changed the local SIP port after. In that case you will need to reprovision the phone.

3CX will not change local SIP port on subsequent phones when you set up EXTs so you'll need to make a note yourself. This is only really a concern if the phones are behind the same NAT.

When setting up STUN phones you should follow this example:

- Ext A should have Local SIP Port: 5065 and RTP Port Range: 14000-14011 (12 ports)
- Ext B should have Local SIP Port: 5066 and RTP Port Range: 14012-14023 (12 ports)
- Ext C should have Local SIP Port: 5067 and RTP Port Range: 14024-14035 (12 ports)
- Ext D should have Local SIP Port: 5068 and RTP Port Range: 14036-14047 (12 ports)
 
  • Like
Reactions: NickD_3CX
Hey @Foiler,

When using the STUN provisioning method, the Local SIP Port for the phone must be whatever you configured it to be in the Management Console >> Extensions >> Edit >> Phone Provisioning >> Local SIP Port of Phone field.

That said, as @kieferschild mentioned, make sure that when logging into the Phone's UI, you are actually looking at the Local SIP Port and not the Register Port. The Register Port field will be populated with the 3CX PBX SIP Port which by default is 5060.

To add to what @kieferschild said, you do not necessarily need to start from port 5065, as long as the SIP Port and RTP Port range used for every device behind the same NAT are unique.
 
On further inspection the Fanvil X3U has been provisioned with Local port 5065 ...
Line - SIP - SIP Global Settings >> Local SIP Port: 5065

Thanks.
 
In the example above, would the router for the 3CX firewall need to have Incoming open ports for UDP: (14000 - 14047), and TCP (5065 - 5068)?
 
In the example above, would the router for the 3CX firewall need to have Incoming open ports for UDP: (14000 - 14047), and TCP (5065 - 5068)?
No, not the firewall that sits between the 3CX server and the internet. These would have to be opened on the Firewall that sits between the IP Phone and the internet (the remove location).
On the Firewall between the 3CX Server and the internet, if your Firewall Checker passes, you should be OK.
 
No, not the firewall that sits between the 3CX server and the internet. These would have to be opened on the Firewall that sits between the IP Phone and the internet (the remove location).
On the Firewall between the 3CX Server and the internet, if your Firewall Checker passes, you should be OK.
I presume you mean that the firewall port rules "opened on the Firewall that sits between the IP Phone and the internet" are only needed for outgoing traffic? ie Just confirming that no pinholes are required for incoming traffic on that router for those ports?
 
Needed is a relative term. If your firewall behaves properly, you won't need any forwarding on the phone side. But if it doesn't then you'll need the SIP and RTP ports (unique per phone) forwarded. Or use a SBC and then you don't need any ports forwarded
 
Hey @Foiler,

What @cobaltit said is true, there are so many different firewall implementations/configurations that we cannot know which applies for every case, so the only way for us to be able to guarantee smooth operation of a STUN configuration is to recommend port forwarding for every remote STUN device, where the SIP Ports and the RTP Port range for every device per site must be unique. You should also check for any SIP ALG features on the remote firewall (IP Phone firewall) and disable them too.
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK