Solved Strange problem with VPN/subnet and 3cx 15.5, Android 15.5.346.651

Status
Not open for further replies.

nobody

Bronze Partner
Joined
Aug 15, 2017
Messages
500
Reaction score
57
I have setup a 3CX pbx at subnet A: 192.168.10.0/24, pbx ip: 192.168.10.20
Firewall check ok, Android phones work ok.
Now, I go with the phone to location B: 192.168.20.0/24
Location B is connected to A using a Lan2Lan VPN.
There is no internal dns at location B which points pbx.A.local to the internal IP Address of A. The DNS record points to the official external IP.
Now, when I start the Android client in lan B, and if I am connected to Bs WiFi, I get the green light, and "on hook" information from the Program.
But if I try to make a call, It stops at "dialing"....also the application will be unresponsive until a timeout occurs.
If I disable Wifi and use the mobile Carrier (lte) everything is fine again.

I went into the profiles settings, and made two changes under Server settings of the account:
Provisiond by the autprovisioning: Local PBX IP: 192.168.10.20, External PBX IP: pbx.somedomain.com

Try1: set the Local PBX IP to the dns name of the pbx instead: Calling works
Try2: set the external PBX ip to the internal IP of the pbx: Calling works also

From this I guess, that the VPN would work for connecting to the pbx. But somehow the android software maybe tried to connect to both the internal and the external address, and then the pbx does not like two connections from a different IP (I had not time to make a wireshark capture)?

During the setup of the pbx, I answered to the question if I have my own dns server with yes. The "Local PBX IP" shouldnt this bet set to pbx.localsubnet.local instead of the internal IP Address of the pbx?

How does the client determine if it is inside the local network of the pbx, and, is a situation like I have here something which have been thought of? What can I do to fix this problem without telling everyone in the Subnet B to switch of Wifi before using the 3CX client?
 
Problem solved: I found out thas also some other services did not work well, like http to a few servers inside location A from B. I lowered the MSS of the IPSec tunnel - one of the endpoints had to use a smaller WAN mtu then 1500. Everything seems to work fine now.
 
  • Like
Reactions: YiannisH_3CX
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK