question about ports

Status
Not open for further replies.

Alex_N

Forum User
Joined
Apr 18, 2019
Messages
38
Reaction score
4
Hello,

I have some problems with the 3cx clients maybe it is the firewall that's why I have some question about the ports.

the pre story:
In our windows clients we use the tunnel with port 5090, it worked well for weeks.
One day suddenly many people at the same time can't be called. Doesn't matter if it is internal or external after 1-2 seconds ringing it says "canceled".
After trying many things (reinstalling the client, restarting the pc, changing some settings etc pp.) I had to turn off the tunnel to make it work again.
This means they should call now via SIP Port 5060 and not 5090. This worked for like 1 or 2 days without any problems and suddenly they don't have any sound when they speak with a customer. I was confused, if it is the firewall, why did it work for like 2 days..
So what I did was to turn the tunnel port 5090 on again. Now they can speak again but I am afraid that the first problem appears again.

Now my question: If I don't use the port 5090 for the windows clients. Which ports need to be opened for the calling? I guess port 5060(sip) or 5061(secure sip) and RTP ports?

We also use a SBC for the IP-Telephones and they run with the tunnel port 5090, but is this port encrypted? if not, how do we use secure sip on the SBC?

thanks in advance.
 
SBC is encrypted by default.
RTP audio port range is 9000 to 10999 UDP

PBx is on premise ? cloud hosted?
 
First question, what is the setup of the 3CX - cloud 3cx or local, how are the phone provisioned (local, STN or SBC)

What version of 3CX
What phones are you using, are you using 3CX application (Windows or Web)

Here are the ports that need setting up - https://www.3cx.com/docs/manual/firewall-router-configuration/
 
Last edited:
Hey thanks for the reply. the pbx is cloud hosted (google), the phones are provisioned with the sbc.
version of the 3cx: 16.0.910 and we are using the windows application.

the windows application also has the option to use the same tunnel port as the sbc. is the windows application also encrypted by default or do i need to turn the tunnel off?

After reading the doc I think it should look like this:
(the firewall says all ports are good but I have one error: it fails to detect the sip ALG server)

Portforwarding from Firwall to pbx :
  • 5090 TCP and UDP for the tunnel
  • 443 or 5001 (TCP) for presence and provisionierung
  • 5060 UDP for SIP
  • Port 5061 TCP for secure SIP
  • Port 9000 to 10999 UDP for RTP
Portweiterleitung forwarding from Firewall to Webmeeting:
- Port 443 TCP to webmeeting.3cx.net

Open ports on firewall:
  • 443 TCP for Google Android Push
  • 2195 and 2196 TCP for Apple iOS Push
  • 2528 TCP for 3cx SMTP Emails
 
Last edited:
That's good, SIP ALG not detected is not a failure, it's good for you not to have on your router.
 
That's good, SIP ALG not detected is not a failure, it's good for you not to have on your router.
11419

it looks like this, the last time time I did the firewall check (some months ago) it was all fine. And we didn't change anything on the cloud firewall.
 
Do you experience some problems, like audio one way ? if not don't worry about this test
 
Rarely I experience problems. No audio problems so far except when I turn off the tunnel port 5090(but I guess it has something to do with our firewall?).
Another example one day if you try to call a 3cx user it says "cancelled" after 1-2 seconds. After I turned of the tunnel port, restarting the client, turning the tunnel on again, it is fixed. But I want to prevent these bugs/problems from happening again.

And second of all I would like to know, if the windows application tunnel port 5090 is encrypted. If not, I will turn it off and need to connect with direct secure sip.

Because if the port 5090 is encrypted for the windows applications, I don't need to turn off the tunnel and that means we don't need to port forward SIP and RTP on our firewall right(because it's not being used)?
 
Last edited:
Hi Alex,

Here is a listing of the ports we currently use https://www.3cx.com/docs/ports/ for setting up your PBX-side firewall.

On the PBX side:
SIP ALG detection failed = the test was not successful so the PBX does not know whether or not your cloud firewall has SIP ALG enabled on the cloud end. You can run the firewall test again to ensure it wasn't a fluke and if it doesn't pass you will need to address it.

On the phones side:
You must ensure that SIP ALG is not active on this firewall either, because it may cause issues to windows clients since they are not encrypted, even if they use the tunnel. The SBC on the other hand should be fine if encryption is enabled on it during installation, since this prevents SIP ALG from inspecting its traffic (hence desk phones would not be facing any issues).

Can you check the two firewalls to ensure they are set up as described?
 
Hello @JohnS_3CX
Right now I can't check the firewall. An other employee will check it when he has the time. btw. our firewall is a sophos.

But unfortunately I don't know if it is possible to look into the cloud firewall which is hosted by google.

For us security is very important. We want to use secure sip, but using the tunnel port 5090 is more simple. So I would like to know, if the port 5090 has 1. an encryption and second if it as secure as secure sip? Thank you in advance
 
The tunnel on the SBC is encrypted and secure (it has an option to enable TLS encryption from the MC).

The tunnel on the app is not encrypted, it just establishes a tunnel connection to the PBX.

You could also consider a VPN between the cloud server and the office, which would automatically encrypt all traffic, and the phones and clients would also appear to be local to the PBX so you would not have to consider ways of securing their traffic over the internet.
 
  • Like
Reactions: Alex_N
The tunnel on the SBC is encrypted and secure (it has an option to enable TLS encryption from the MC).

The tunnel on the app is not encrypted, it just establishes a tunnel connection to the PBX.

You could also consider a VPN between the cloud server and the office, which would automatically encrypt all traffic, and the phones and clients would also appear to be local to the PBX so you would not have to consider ways of securing their traffic over the internet.
Thanks this was the answer I was looking for. This is enough information for now.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,932
Messages
589,805
Members
164,804
Latest member
fcentral