Solved SIP Server/Call Manager ID: 12293 DNS error resolving FQDN, or service is not available

Status
Not open for further replies.

denko2k

Customer
Joined
Mar 20, 2018
Messages
63
Reaction score
6
Setup:
PBX: 3CX (always latest stable version)
firewall: pfsense
IP: dynamic, changes every 24 hours at 23:00
STUN-Servers: stun.3cx.com, stun2.3cx.com, stun3.3cx.com
2 SIP Trunks: "sip.dtst.de" and "tel.t-online.de"
DNS Servers: 8.8.8.8 and 8.8.4.4

Everything works fine; problem related things where tested:
firewall NAT works (“pure NAT”) is configurated
3CX firewall test works fine
Ping to both providers work
NS lookup is correct
No issues with calls, etc. on both trunks

Problem
Since a few days the following issue occurs:
After IP address changes (at 23:00) the trunk to “sip.dtst.de” does not longer register.
Event ID:
SIP Server/Call Manager ID: 12293
Registration at DTST has failed. Destination (sip:[email protected]:5060) is not reachable, DNS error resolving FQDN, or service is not available.


The Trunk to “tel.t-online.de” still registers.
After a restart of the firewall (IP changes again), all trunks work fine.
Restart of the 3CX Services or the Server does not help.

If the resolved IP instead of “sip.dtst.de” is set into the trunk, the same event ID (error) is shown.

The service "sip.dtst.de" is not down (we have a test trunk on another non-3cx-system and it works) and the issues only occurs when the IP changes.


Can anyone help?
Thanks a lot.
 
Hello @denko2k

So the issue presents it self as soon as the IP changes and it is only resolved when the firewall is restarted? Do you see anything blocked on the firewall at the time of the error?
 
  • Like
Reactions: denko2k
Hello @YiannisH_3CX

yes. As soon as the IP changes, the issue is present.
I can not see any firewall logs which point to the issue
 
In this case you could run a wireshark capture on the PBX machine while you restart the PBX services. You should see the PBX trying to resolve the IP address and then send a register message to the provider.That should point to the issue. Check if the register is sent to the correct IP and check if there is a reply from the provider.
 
  • Like
Reactions: denko2k
Hello @YiannisH_3CX

Thank you.

With wireshark we found out that 3CX tries to register the trunk but does not get any answer.

Cause
The issue was caused by pfsense because it does not kill the firewall states when the external IP changes.
On my system the default size is: 1223000 (Firewall Maximum States)
On my system the default size is: 800000 (Firewall Maximum Table Entries)
In case if IPv6 is used and Bogon network information are up to date, the number of max entries had been extended.

Resolution
Tell pfsense to kill all states when the IP changes (when the gateway goes down).
In pfsense go to:
System >> Advanced >> Miscellaneous
Scroll down to: Gateway Monitoring >> “State Killing on Gateway Failure”
Activate “Flush all states when a gateway goes down”

Side effects
All states get killed; web sessions get killed as well when the gateway fails/gets a new IP.
But this should not be a problem in SMBs, when the IP changes in the middle of the night.


Maybe you could add into the documentation "3CX with pfsense":
In case of using dynamic IPs: let pfsense kill firewall states when the gateway fails/gets a new IP.
 
Glad to issue has been resolved and thank you for sharing your solution. I will see what can be done about the guide.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,885
Messages
589,547
Members
164,745
Latest member
Herm77