Real world cloud based 3CX - SIP and RTP ports

Status
Not open for further replies.

rc179

Silver Partner
Basic Certified
Joined
May 1, 2020
Messages
97
Reaction score
11
This is the scenario;
Cloud based 3CX, no SBC, Yealink phones
Whenever I've done a similar system whether it's a major name or Asterisk variant, I use SIP port 5060 and an RTP port range and these are the same for all phones. For example, I would provision the phones for SIP 5060 and RTP 14000-14100. And all the phones would share these settings.

But with the 3CX I'm told that each phone needs to be on a unique port for the SIP, so phone-a has SIP 5061, and phone-b has SIP 5062, and so on so that phone-z would have SIP 5086. And phone-a would have RTP 14000-14019 and phone-b would have RTP 14020-14039 and so on through phone-z at 14500-14519

Is this how you've done it in a similar environment?
 
Again, I must be lucky. I've got intercom working on STUN extensions no problem.
Hmmm Interesting. What's your firewall at the site and do you have sip-alg enabled? And is the cloud 3CX PBX behind a firewall or is it just what's built in? I'd love to know why the results were different.
 
Hmmm Interesting. What's your firewall at the site and do you have sip-alg enabled? And is the cloud 3CX PBX behind a firewall or is it just what's built in? I'd love to know why the results were different.

Phones are sitting behind a Sophos SG210. No ALG active from memory. Cloud PBX is on AWS. No standalone firewall on that end.

Maybe I shouldn't say too much. I'll get a phone call tomorrow from clients telling me it's not working
 
  • Like
Reactions: Evolute IT
Thanks, if I can find some time I'll set up a dozen test phones and capture some traffic to see exactly what is happening.

Of course there is still the issue of 3CX clarifying if this is supported or not.
 
I don't see where the confusion is. It's already been stated what is supported. SBC or STUN with specific port forwarding. Can it work without the specific port forwarding? Yes. Is it 3CX supported, no. You talk about budget but 3CX + whatever it costs for SBC/HA SBC/VPN is still generally going to be cheaper than another solution. It might be that you a confusing 3CX support for something like Cisco TAC. It isn't even close. Basically if you setup phones via STUN without port forwarding and you have audio issues, the first thing 3CX support is going to do is ask you to do is to ensure the supported environment:

- Firewall checker passes
- Current 3CX version
- Current 3CX firmware and template
- STUN setup without overlapping ports and port forwarding on the endpoint side.

And somewhere along those lines it will start working because generally it's deviating from the 3CX tested configurations that cause problems.

It's really that black and white. There are partners that don't follow 3CX supported configurations and do very well for themselves but they've built and tested their solutions and thus support it themselves. You have the option of doing it that way, doing it the 3CX way, or finding a solution that better suits you.
 
We deploy SBC's on all remote installs, thus not needing to open tuns of ports, as well as better performance all around. We also have had to repair many other systems setup by other partners using STUN connections. A PI is a very cheap solution to solve tuns of problems, and by installing Teamviewer on the PI, now you have remote access to the phones. WIN WIN.
 
I don't see where the confusion is. It's already been stated what is supported. SBC or STUN with specific port forwarding. Can it work without the specific port forwarding? Yes. Is it 3CX supported, no. You talk about budget but 3CX + whatever it costs for SBC/HA SBC/VPN is still generally going to be cheaper than another solution. It might be that you a confusing 3CX support for something like Cisco TAC. It isn't even close. Basically if you setup phones via STUN without port forwarding and you have audio issues, the first thing 3CX support is going to do is ask you to do is to ensure the supported environment:

- Firewall checker passes
- Current 3CX version
- Current 3CX firmware and template
- STUN setup without overlapping ports and port forwarding on the endpoint side.

And somewhere along those lines it will start working because generally it's deviating from the 3CX tested configurations that cause problems.

It's really that black and white. There are partners that don't follow 3CX supported configurations and do very well for themselves but they've built and tested their solutions and thus support it themselves. You have the option of doing it that way, doing it the 3CX way, or finding a solution that better suits you.
It's not clear, and you are not 3CX, you should not be making statements on behalf of them.... or have they authorized you to speak on their behalf?

@JohnS_3CX who is a 3CX representative has stated "we don't by any means prevent you from deploying the phones in STUN using the same ports, on the contrary, the system allows you to use the same ports for all during provisioning." This sounds like 3CX is OK with this implementation, but that conflicts with what other sources say, because the means by which they prevent it is to completely deny you any support. And what you can't be doing is rebuilding an environment, with additional equipment and interrupting services to the customer, any time you need assistance. That's just plain irresponsible.

And I'll remind you that initially, before this thread, 3CX support stated " Each IP Phone requires unique local Sip and local RTP ports." That's pretty clear. They did not say it's unsupported, they said "requires unique local Sip and local RTP"

All I want is a yes/no response from 3CX.
Is it nessisary for operation (unique SIP/RTP ports)?
Is it supported (using the same SIP/RTP ports)?

The real work examples answers one of these, but it's not Official until 3CX says it.
 
We use cloud managed/monitored EdgeMarc 2900e Routers in a lot of implementations where for whatever reason an SBC set up wasn't wanted, Works incredibly well and also gives us direct secure VPN to each site to interrogate the phone GUI's if needed... we have a couple of sites with 200+ IP Phones all working without issue...

Everywhere else we use Pi or other Debian based machines (some VM) for SBC's locally....
 
Last edited:
You are a 3CX Partner, so if the procedures are not clear to you please speak with Support or your Representative to get clarifications directly.
 
  • Like
Reactions: cmp1
Status
Not open for further replies.

Forum statistics

Threads
111,952
Messages
589,895
Members
164,845
Latest member
tdzski5