SBC controller showing as "inactive" in Teams admin

liambm

Customer
Joined
Oct 8, 2019
Messages
6
Reaction score
0
Hi

I'm attempting to implement the 3CX/Teams integration, however having a lot of difficulty in getting the SBC controller to connect (using a custom domain and on-prem 3CX appliance). No matter what I seem to do the "TLS connectivity status" for the SBC shows as Inactive and I'm unable to make or receive calls via Teams.

I've checked the following:
- Generated SSL certificate and private key using SSL.com and uploaded in 3CX config
- Using a custom domain so have also added the SSL certificate and private key under "Secure SIP" in 3CX config
- Configured Azure AD app using the certificate file generated from 3CX M365 config and otherwise correctly configured
- Ensured port 5062 is open and forwarded to our 3CX server
- Repeated the install process roughly 35 times

Any assistance would be greatly appreciated. I've spent hours on this and don't seem to be any further along.

EDIT: in the usage logs for the SBC I have the following errors:
407
560407
Proxy Authentication Required - Check the SBC configuration


504
569002
Server Time-out - TLS misconfiguration on the SBC
 
Last edited:
Regarding your question, and when you say you use custom FQDN, this relates to using a custom FQDN for the PBX HTTPS certificate? as the team's FQDN will always be a custom FQDN. If a custom FQDN is being used for the PBX and the same FQDN for teams, then yes, you will need to add the certificate, intermediate, and ideally the root certificate and private key under the Secure sip section and restart the 3cx sip server services, but in this case, the port required to be opened will be 5061 not 5062: see this guide for more info: https://www.3cx.com/docs/microsoft-teams-integration-faqs/
 
Hi Charles

We have a custom FQDN for the Teams integration (teams.businessname.com.au), but the standard accountname.3cx.com.au FQDN for 3CX in general.

So should the certificate under "Secure SIP" be the same as the certificate for the Teams integration, or should it be a different certificate for accountname.3cx.com.au?

Thanks
 
The certificate under the secure sip will be the certificate for the pbx in your case, there is no need to replace the certificate there. All certificates for teams are custom and the days domain must match the email domain within 365. The certificate used for teams must not be a wildcard though. So for example business.Com.au is you email domain in 365.
 
Yeah that's all understood. I've tried it with the SSL.com certificate for the teams.businessname.com.au domain in secure SIP, and the SSL certificate that was in those fields by default. It doesn't seem to work either way. The domain for which the SSL.com certificate has been issued is the same as the 365 domain, so that shouldn't be the problem either.
 
I would suggest restoring the original configuration for the secure sip and restarting the sip server services, then ensuring that the team's FQDN also points to the PBX public IP address. Ensure that the certificate used for teams has the intermediate and root certificates entered and is not a wildcard certificate, wildcard certificates are not supported for SIP TLS.
 
Thanks, however I have already tried that (a couple of times). The SSL certificate for the teams FQDN was issued by SSL.com in accordance with the 3CX guide, so I can only assume that it's correct.
 
In this case, and assuming that you have generated both the dial plan and the user script, run them via PowerShell. and have the dial pad with the correctly formatted number in E164 format. I suggest logging off from the teams app exiting it, then re-open and try to call again, if this does still not work, and if you are sure you have gone through checking the FAQ for further troubleshooting, then all I can suggest here is to open a ticket with 3cx tech support to assist you further as logs are going to be required to check this further.
 

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK