Sip VIA: header

Status
Not open for further replies.

ben rooke

Gold Partner
Advanced Certified
Joined
Mar 25, 2019
Messages
50
Reaction score
2
We have an issue where we are using an edge solution that needs the VIA header in the SIP messages to be the public IP of the PBX but it comes up as the private IP.... is there a way to change this?
 
What have you tried so far?
 
We have an issue where we are using an edge solution that needs the VIA header in the SIP messages to be the public IP of the PBX but it comes up as the private IP.... is there a way to change this?
For trunks you can navigate into the options tab and enable the option "Put Public IP in SIP VIA Header"
 
Right now, not a great deal on the basis that my MD has advised that this is not something we should / can do. i was just looking to find out if this is something that can be done or if anyone has had need to do something similar. There is a setting on the Trunk to use the public IP as via.., but was advised not to use this..
 
Right now, not a great deal on the basis that my MD has advised that this is not something we should / can do. i was just looking to find out if this is something that can be done or if anyone has had need to do something similar. There is a setting on the Trunk to use the public IP as via.., but was advised not to use this..
i think this is because they also need if for the extensions.
 
There is a setting on the Trunk to use the public IP as via.., but was advised not to use this..

Advised by who, and what was the reason for this advise ?

We have the setting "Put Public IP in SIP VIA Header" turned on in pretty much all of our IP authenticates SIP trunks (Gamma/Twilio) we have had a few cases where calls won't work without it.
 
basically what we are trying to do is put in an edge solution that moniors all SIP traffic in and out of the lan, as well as on the lan itself, in order to do this it needs the via header to show the public IP on both the trunk and the extensions... i assume changing the option on the trunk will only do this at the trunk...
 
i assume changing the option on the trunk will only do this at the trunk...

Yes that is correct.

Edge solution ? normally an SBC (Edgewater/Ribbon/Audiocodes) will provide this sort of service - is this what you are using ?
 
Yes the option will only enable the via only for calls going to the provider. The extensions do not have this option as calls from extensions are routed through the PBX.
Also if the extensions are on the same LAN as the PBX the VIA should always include the local IP of the phone.
 
Yes that is correct.
Yes the option will only enable the via only for calls going to the provider. The extensions do not have this option as calls from extensions are routed through the PBX.
Also if the extensions are on the same LAN as the PBX the VIA should always include the local IP of the phone.

its a hosted PBX so the edge solution would be situated at the remote office... i think this is where it was falling over a little...
 
In response to your comment:

"its a hosted PBX so the edge solution would be situated at the remote office... i think this is where it was falling over a little..."

What is this solution, do you know the details ? As I mentioned earlier it sounds like an SBC type of solution. Proper SBC's can either sit locally and deal with traffic on the local site (add security and collect call related data). Or they can sit in the cloud on a providers edge and facilitate remote connections from multiple customer sites.

You will also often find SBC's are dedicated to one type of traffic (either SIP or media) if being used by a provider.
 
@ben rooke I am going through this exact issue right now. Trying to get the Edgemarc to work with 3CX when hosted. Edgemarc is telling me that the 3CX PBX is "incorrectly" (their term, not mine) sending the local IP in the VIA header rather than the public IP, and that is causing inbound calls, presence info and other items to not function.

I'm wondering how others have their Edgemarcs working with 3CX? Do they have their 3CX modified in some way, or are their 3CX PBX interfaces literally configured with public routable IPs? Is their 3CX not in AWS or Azure? Perhaps a VPN between the host and the Edgemarc? i'm trying to understand how we feel like the first to discover this issue...? Curious what your experience has been thus far.... I'm ready to return the Edgemarc for a refund.
 
I know of several partners who use Edgemarc's with 3CX, we don't however. What I do know from my experience with the devices (as I have tested them) is that you can connect using Direct STUN/SIP or via VPN connection (for endpoint connection(s).

VPN obviously would be preferable and probably better although does inhibit the information that can be taken onsite regarding endpoints/MOS scoring etc.
 
All of my 3CX (20+) implementations have an EdgeMarc 2900x installed. All of the 3CX PBXs are hosted in the cloud. The PBX is setup as normal, the phones are configured with Direct SIP (Stun Remote). I use EdgeView to capture packets and monitor the internal LAN and the external WAN. Works great, all of the time.
 
And you use secure SIP and SRTP if using phones in STUN mode I would presume?
 
All of my 3CX (20+) implementations have an EdgeMarc 2900x installed. All of the 3CX PBXs are hosted in the cloud. The PBX is setup as normal, the phones are configured with Direct SIP (Stun Remote). I use EdgeView to capture packets and monitor the internal LAN and the external WAN. Works great, all of the time.
Would you be willing to do a phone call with me to discuss? Happy to pay for your time. Obviously I/we are missing something, as are the two EdgeMarc distributors and Ribbon support themselves in trying to get this to work for me. So far, the conclusion is that I cannot use the standard PBXEXPRESS Azure install since it creates the NIC with a private address and NATs to a public IP. I'm being told the actual NIC of my PBX must be assigned the public IP for it to work. I'm hesitant to do that , as I don't view it as particularly secure, so I'm curious what other solution there is. Not to mention I paid for an Edgemarc that is completely useless at present. Thank you.

PS: If we did a call, I'd of course post the result of the call here so the entire community could benefit...
 
Negative on the Secure SIP. The 3CX PBXs are all public IPs running Debian. I use IPSET and DENYIP to lock the system down as tightly as possible. IPSET is setup with a "negate" filer block ALL traffic outside of the USA. There is ZERO reason any traffic outside the USA should even hit the PBX. DENYIP blocks the SSH probes and login attempts.

The EdgeMarc 2900x handles all of the SIP Proxy security to the phones on-premise. It also handles all
of the topology hiding by modifying the SIP Header with the Public IP Address. I also run Skype for Business through the same 2900X and the 3CX soft client (port 5090) at the same time along with the Yealink phones (port 5060).

No reason to run SRTP unless you really want to or need to; the SIP trunks to the PSTN typically don't support it so why complicate things?
 
Darren you have my email address from a couple of weeks back. Reach out and I will help. I am available this weekend and traveling all next week.
 
Status
Not open for further replies.

Forum statistics

Threads
111,930
Messages
589,801
Members
164,803
Latest member
fcentral