• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

Solved SBC incoming ports

Status
Not open for further replies.

ozydave

Premier Customer
Joined
Jul 22, 2021
Messages
14
Reaction score
2
Hello,

I have had to host my 3CX server in the cloud. So had to deploy an SBC (its on windows).
After getting someone on the firewall to open ports the 3CX can now see the SBC. (its lit up green so assume all good)

So plug a phone in, its on the same VLAN as the SBC. The phone gets a DHCP address (from my servers) and I can see it in the 3CX 'phones' section.
The phone will not provision. I have manually assigned the phone to an extension, still no joy.

Checking the SBC logs I can see various lines relating to the phone IP address as below
I guess the line SIP/2.0 500 Server Internal Error might be the problem.

DEBUG | 20210722-111622.344 | 3CX | SBC | 4968 | TunnelTcp.cpp:559 | RX TCP Sip0 of len 462
INFO | 20210722-111622.344 | 3CX | SBC | 4968 | BridgeTunSip.cpp:28 | RX tun:
SIP/2.0 500 Server Internal Error

The 3CX is 16.0.8.9 version and the phone is a Yealink 41s with firmware 66.86.0.5

I just wondered if the SBC needs incoming ports opened 5090 5001 maybe.
I don't control the firewall

Regards
 
No port forwarding is required on the firewall protecting the SBC, it is all outgoing traffic.

Are you blocking the 3cx https outbound port - 443 or 5001 tcp port as this is needed for the provisioning url

Have you run the firewall rules within the 3CX management console ? , and errors ?
 
Hi Dave,

The SBC does not require any port forwarding at all. Your firewall must however allow outgoing TCP connections, so the SBC can go find the PBX. Same goes for phones, no port forwarding is required but your firewall must allow outgoing TCP connections, so the phone can go find the PBX and fetch its provisioning.

So I guess the question would be whether you are blocking outbound traffic in any form or way
 
Cheers
The firewall checker within the 3CX is all green no errors.
Could do with a similar firewall checker inbuilt into the SBC

To try and narrow down the problem the firewall (or so i am told) has an any, any outgoing rule applied. Traffic from my internal SBC hits the firewall and all outgoing ports are allowed.
 
Hi Dave,

The SBC does not require any port forwarding at all. Your firewall must however allow outgoing TCP connections, so the SBC can go find the PBX. Same goes for phones, no port forwarding is required but your firewall must allow outgoing TCP connections, so the phone can go find the PBX and fetch its provisioning.

So I guess the question would be whether you are blocking outbound traffic in any form or way
Ah,

That might be it then. Only the SBC IP X.X.30.3 has been configured to allow outgoing ports.
So your saying the phones on the VLAN X.X.30.0/24 woudl need to allow outgoing ports?
 
Exactly, so that the phones can download their provisioning and other stuff like their phonebook and firmware.

The SBC only deals with calls - it does not generate provisioning files etc.
 
  • Like
Reactions: Evolute IT
Ah,

That might be it then. Only the SBC IP X.X.30.3 has been configured to allow outgoing ports.
So your saying the phones on the VLAN X.X.30.0/24 woudl need to allow outgoing ports?

Yes, phones

1. 3cx https port access to your 3CX fqdn. This is used to provision the phone using the 3CX provisioning url, phonebook access

2. ntp (udp port 123) access to pool.ntp.org (unless you have changed the default setting)
 
Ah,

That might be it then. Only the SBC IP X.X.30.3 has been configured to allow outgoing ports.
So your saying the phones on the VLAN X.X.30.0/24 woudl need to allow outgoing ports?
Yes so that phones can contact the PBX and get their provisioning.
 
You guys have been really helpful and quick

I have just made a request to the firewall team to make the changes. Will post back with the outcome.
Its in the lap of the gods when they will make the changes though :-(
 
  • Like
Reactions: JohnS_3CX
Let us know how it goes. In the meantime, you can factory reset your phones so they are sitting there ready for when the time comes.

As soon as the firewall actions are carried out, you can simply assign a phone from the "Phones" page on your management console, and give it a minute to automatically fetch provisioning and reboot.
 
All sorted now.
With the firewall ports opened and a factory reset on handsets, they all provisioned as they should

Thank you all for your help.
 
Excellent news Dave! We are all glad to help!
 
Status
Not open for further replies.

Forum statistics

Threads
112,147
Messages
590,959
Members
165,167
Latest member
Finatra.us