SBC outbound ports on restricted firewall.

Status
Not open for further replies.

hogan71088

Gold Partner
Joined
Nov 30, 2015
Messages
144
Reaction score
36
Hi all,

Working on a firewall where the site won't allow outbound traffic fully on the phone network. The phones are behind an SBC. Ports 5001 and 5090 were allowed out but its seems this is not enough. I can't find any definitive answers in the documentation.

An example would be each individual phone needs to be allowed out to contact pool.ntp.org to update the time on port 123 so this needs to be added to the rules.

Can anyone advise on other outbound ports?
 
vpn tunnel or cheat like hvac people and install cable/dsl behind firewall change route of the phones to the cable/dsl.
 
vpn tunnel or cheat like hvac people and install cable/dsl behind firewall change route of the phones to the cable/dsl.

Not an option. Have to work with what's there.
 
listed under functions of a sbc is "VPN connectivity" sbc your just giving it more connectivity by making it a full vpn tunnel :D
 
outbound ports are 5090 udp and tcp (3cx tunnel) , 3cx https port (port 443 or 5001) and ntp port (udp 123)
 
https://www.3cx.com/docs/manual/firewall-router-configuration/

I think NTP is the only port not listed, although that's not technically required for phone operation.

Correct, phones can pick up time from the local DHCP server during first boot but its best to allow NTP to keep things synchronized correctly.

@hogan71088 You need to find a way for that specific firewall to allow you to do what you want, ensure encryption is active on the SBC to increase your chances but if you cannot find documentation or a way around it, this firewall may need to be replaced (ouch)

Have you tried contacting the original firewall vendor/installer/administrator?
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,821
Members
164,812
Latest member
martin99