Solved Remote Provisioning - Direct SIP (STUN Remote) - Port Forwarding Requirements

Status
Not open for further replies.

Alan9846

Silver Partner
Joined
Aug 24, 2019
Messages
96
Reaction score
19
Hi All,

When we provision a phone remotely (and there is no SBC or VPN available), we follow the guide that is provided here to use Direct SIP (STUN Remote):

https://www.3cx.com/docs/manual/configuring-ip-phones/#h.c6ea5z2ao7tv


Unless I missed it (always possible!) there is no mention on that page of us needing to setup any port forwarding on the router where the phone is based, except in the 'see also' section at the bottom.

However, there are posts in the forum that talk about having to do port forwarding, such as:

https://www.3cx.com/community/threa...netgear-nighthawk-x4s-d7800.54620/post-225296


Is port forwarding still required, or was that post from a time when things were different?

Thanks,

Alan.
 
Yes it is still required to be fully supported and avoid any issues. Also disable SIP ALG.

You'll need to refer to your firewall's manufacturer to learn how to do it on your specific router.
 
Hi Frederick,

Thank you for replying

What are the implications if the port forwarding is not in place?

I have just tested this without port forwarding, and everything seemed to work fine, but I am guessing something bad could happen and / or the phone might suddenly stop working?


Thanks,

Alan.
 
Hi Alan,

The direct implications are that it may stop working when you least expect it because the decision-making was left up to the automated algorithms of your router/firewall rather than being put hard in place.

Forwarding is required - please visit the link posted above by @cobaltit and it should make things a bit more clear
 
  • Like
Reactions: Evolute IT
Hi Guys,

I'm sure you are right - I'm not doubting at all, and if possible I'd always have clients configure the firewall / router, but in some remote locations this is not as easy as we might hope, and we are not always the IT support unfortunately.

Also odd that you guys are clear this needs to be done (as is the document linked by CobaltIT), but 3CX do not make any mention of it in the official configuration documentation (see link in my OP). Could just be an oversight / error on their part perhaps?


Thanks,

Alan.
 
Hi Alan,

Not at all, the guide covers the phone configuration specifically, so it won't be going into the details that have to do with your networking setup. We cover the subject adequately in our 3CX Academy.

I highly recommend taking advantage of our Academy if you manage your own 3CX system!
 
Last edited by a moderator:
  • Like
Reactions: Evolute IT
Yes - I noted as much. Definitely something they need to work on in relative terms, but 3CX is hardly unique in that respect.

I've been through most, maybe all, of the Academy stuff, just never bothered to do the 'exams' as I've yet to meet a client who cares about it in any of the installs I have done over the years. I should probably go back and do them I guess, but it seems like a lot of time spent for little gain.


At the end of the day, for the remote IP Phones where we only support their telephony, and not their IT generally, all we can really do is advise clients that they need to set a fixed IP and port forwarding - I will advise them that if not, it might cause problems, and hope that they comply. Its becoming much less of an issue anyway, as very few people are using IP Phones remotely now, its nearly all Android, and that side of things seems to be pretty much rock solid.


Thanks,

Alan.
 
Yes, STUN pretty much universally relies on some form of port-control, and its best to do it manually rather than let the firewall do its thing automatically.

I would inform the customer that we either do it right and have peace of mind, or you use the app which works without any additional actions.

For cases where there's more than 1-2 phones, the Raspberry Pi or a local VM for SBC are excellent options which again negate the need for any of the STUN requirements at the remote site
 
  • Like
Reactions: Evolute IT
Just one IP Phone at that location, else we would have suggested an SBC, but for one phone, I can't see it being worthwhile.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet