Reverse proxying 3CX no audio

ConnextekInc

Silver Partner
Advanced Certified
Joined
Jul 5, 2024
Messages
5
Reaction score
2
Hi,

As our 3CX instances number is rising, we are in a process to merge them under a single WAN IP using a NGINX or HAproxy server. So far the web page is showing correctly, however we are facing some issue:

Web console calls are working but no audio is going through. Upon further investigation, we noticed in the STUN binding process that the remote 3CX or NGINX is returning the local IP address of the PBX, making the bind impossible. Even though we tried setting 3CX to use a stun server, using NGINX with an x-forward, whatever we do, the webclient always return the pbx local IP.

Would you have any idea if this behaviour seems related to poor firewall/natting configuration, NGINX config, or just a limitation of 3CX ?

Thank you
 
The web traffic should not be proxied. It should go directly through to the PBX.

Every system should be under its own IP Address. If you have a requirement for multiple systems in one network, you may want to look into deploying a 3CX Multi-tenant and having all your smaller instances going on this.
 
Hi Nicolas,

Thank for your reply. I do understand this is not a supported feature by 3CX and we are not excepted to receive any detailed instruction on how to do so from 3CX, but if we look at it on a networking side, there shouldn't be anything that preventing it to work.

Port 5001 --> Proxied to Haproxy
Port 5090 --> Proxied to Haproxy
Port 7000-10999 --> Proxied to our SBC
Port 5060-5061 --> Proxied to our SBC

This setup works for phone provisioning, desktop and mobile apps. Only issue is webclient calls with no audio. Remote endpoint always trying bing to the PBX local IP.

Would you be able to confirm if there is a mechanism in place in 3CX that would ultimately prevents us from accomplishing what we want ?
 
i think your problem is related to SIP/RTP itself. You have IP/Port combinations defined in the SIP protokoll and your web proxy scrambles this to other ports. Also reverse proxys and UDP are not best buddys. The reason why smartphons and V20 App is working. They use 3CX Tunnel protocol.

The Webclient uses STUN to detect the public IP and trys a direct connection.

In a nutshell, using a reverse proxy = you cant use webclient for calls, just for CTI
 
i think your problem is related to SIP/RTP itself. You have IP/Port combinations defined in the SIP protokoll and your web proxy scrambles this to other ports. Also reverse proxys and UDP are not best buddys. The reason why smartphons and V20 App is working. They use 3CX Tunnel protocol.

The Webclient uses STUN to detect the public IP and trys a direct connection.

In a nutshell, using a reverse proxy = you cant use webclient for calls, just for CTI
Hi, thanks for the info.

But I've had trouble figuring out what big 3CX partners reselling tons of 3CX instances do. Do they really use dedicated WAN IP per 3CX instance ? The multi-tenant feature can be interesting for small clients but it becomes a mess quickly once you merged larger companies. Would a partner reselling a thousand big 3CX instance really dedicate a single IP per instance ?
 
one instance, one ip... thats it
When it comes to security and data policy. Having a single ip with rules that are fixed on that one IP are much easier to handle in greater networks
 

Latest Posts

Forum statistics

Threads
111,962
Messages
589,996
Members
164,868
Latest member
swegner