Server Error Management Console

Status
Not open for further replies.

dpitchfo

Customer
Joined
Oct 26, 2018
Messages
7
Reaction score
0
Help - Not sure what is going on or how to get this resolved. I am unable to login to the management console. I am hosting a sever on ESXi 6.5 server and able to log in the command line no problem. But the management console using Chrome and Firefox fails. I have tried using the IP address and the Domain name url, as well attempts from from multiple IP addresses and computers. I have reboot server and checked that all the service started up (# service 3CX* status) and they do without any errors.

Last month I started receiving HTTPS certificate are not being renewed: Email message below

HTTPS Certificate renewal Failed - Network problem
SSL certificate failed due to network conditions. Unable to reach Certificate Issuing Servers. The process to renew your certificate will start again in a couple of hours.


Could these issue be tied together?

Any thoughts? I am thinking of wiping the server and restart. My backup jobs are working or the email says they are working. The phones are also all working. So don't know what the next step is.



1597684362991.png
 
I have a new install that I just brought up in the last couple of weeks and mine started doing this to me today as well. I went home Friday, came in this morning, and it broke itself over the weekend.
 
I think 3CX moved the license server to new country.

So I decided to blow away my old server and reinstall it. During the installation process I realize that the the system could not reach the license server. I had to whitelist the server (bypassing all my rules) allow access to the license server. Once I whitelisted the server, my console came back. I am able to log back in. I looked at the firewall log and notice connections to sites outside of the US. One of the big one was downloads-us.3cx.com which is actually in Perth Australia (or we think).

So before doing what I did, check your firewall rules. 3CX server are on the move.
 
I updated my Meraki config so my country blocks didn't apply to the 3CX server and now I can log in to the management console. It must have been blocking communication to a 3CX server like you said. Thanks!
 
@dpitchfo i imagine the issue is now resolved after the reinstall?
 
I updated my Meraki config so my country blocks didn't apply to the 3CX server and now I can log in to the management console. It must have been blocking communication to a 3CX server like you said. Thanks!

Question - Just curious what did you do to add rule to meraki?
What I did was to add an outbound rule (Security & SD-WAN -> Firewall -> Outbound) rules to allow TCP Port 443 from 3CX IP Address to "downloads-us.3cx.com". Is this the same thing you did?
 
@dpitchfo i imagine the issue is now resolved after the reinstall?

Reinstall did not fix the issue. The issue was caused by 3CX moving the instance of "downloads-us.3cx.com" from a US Based server to Google Cloud that is hosted in Australia / Perth (or I think it is hosted there). My firewall rules blocked the 3CX Instance from talking to foreign entities for numerous reasons.

I had to add a rule to allow it talk to this URL so now it is working now (this was the root cause). Question for 3CX - Why if I am hosting my 3CX Instance and the act of logging on requires to communicate with "downloads-us.3cx-com". Makes me worried that their is a backdoor to the PBX / Server.
 
I read somewhere you should try to bypass as much filtering as you can for VoIP so I created a group policy under Network-wide > Group Policies. In the policy I selected "Custom network firewall & shaping rules" and did not add any firewall rules. I added a shaping rule to prioritize VoIP traffic. I disabled AMP, override blocked website categories and blocked URL patterns. Then under Network-wide > Clients I applied the policy to the 3CX server. I have 1:1 NAT rules under Security & SD-WAN > Firewall to NAT the traiffc to 3CX.

I'm not sure this is the best way to do this though. I would be interested in what is the most secure/most restrictive way to set this up where 3CX will still function.
 
Last edited:
@dpitchfo block it again (only that URL) and see if you can replicate this behavior. I'm not convinced that blocking that URL will directly prevent you from logging in, and suspect that something else was happening in your case other than this specific block. The back door worry is not justified.
 
Status
Not open for further replies.

Forum statistics

Threads
111,956
Messages
589,928
Members
164,860
Latest member
maxpcc