STUN + NAT Configurations

Status
Not open for further replies.

Lenin K

Silver Partner
Advanced Certified
Joined
May 23, 2018
Messages
14
Reaction score
3
Hello 3CX Community,
Was hoping to reach out to some users with some STUN experience. Currently, we have a client who has three different sites, and all phones are configured via STUN to access the 3CX PBX VM in the cloud. We noticed with this setup (as well as another similar cloud setup for another client) that the traffic is not being properly translated back to the phones. I can see the phones going out just fine, however, some of the audio appears to be lost on its way back to the office. Has anyone experienced this before?

Now before anyone says this is a firewall issue, I'd like to get some insight & see if anyone else is experiencing this issue with any STUN setups. It could be a SNAT issue, however, there has to be a setting, or at least another, that we can enable to let the PBX system deliver all necessary packets to the phones via STUN.

Any suggestions, or idea+brainstorming would be greatly appreciated! Thanks
 
Hi

Worth looking to see if there is some kind of SIP ALG going on the router and or the firewall? However the best way to get round this is
Select the extensions at one of the sites. Select extension and then tab across the top to Options and once in there at bottom select PBX Delivers Audio.

This increases the packet traffic very marginally but it will fix the problem. I used this to resolve multi site STUN with NAT setups.

Hope this helps
 
  • Like
Reactions: Lee Cramman
Thanks for the suggestion Sergio. I've confirmed that SIP ALG is not enabled on the firewall, and the PBX is delivering the audio for all STUN configurations. If there is no fix for this, definitely would be something to look into. One alternative would be to use the Session Border Controller on a PC within the network
 
Define "some audio is lost". Do you mean one way audio, or jittered audio ?
 
Hello @Lenin K

When dealing with multiple STUN devices in a remote office and facing audio issues you need to make sure that each phone has its own dedicated SIP port and audio ports.
You need to assign different ports to each phone through the extension settings in the management console and port forward these ports to the local IP of each phone in the remote office.
You will then need to re-provision the phones to make them aware of the new ports.
If you use wireshark on both ends you will able to track a call. If you see the phone requesting audio on a different port but the PBX is receiving a different port then that could indicate that a firewall has SIP ALG enabled or some kind of port translation.
https://www.3cx.com/3cxacademy/videos/intermediate/configuring-remote-extensions/
 
@saint_ Apologies, I should be more specific. The end users are reporting jittered audio

@YiannisH_3CX - I've configured each STUN device to function on their own SIP port, and I've also assigned each extension a different set of 20 RTP audio ports. When the traffic comes back, it does not appear to be routed to back to the phone, but it hits the WAN IP & drops. SIP ALG is not being used

I've confirmed that this issue is occurring with more than one of our 3CX cloud setups
 
@YiannisH_3CX Thanks for sharing that link. Please review my screenshot. Does this mean I will need to setup a NAT rule for every device on site that using a STUN configuration to the 3CX server?
 

Attachments

  • Capture.PNG
    Capture.PNG
    49.3 KB · Views: 52
Yes
https://www.3cx.com/docs/provisioning-remote-extension

Notes when using Remote Extension with STUN:
  1. Please make sure that your Remote Location has Static NAT implemented as well to the phones and that the SIP port and RTP port range for each phone as specified in Extension Settings >> Provisioning tab is correctly forwarded to the IP address of each phone
 
Does this mean I will need to setup a NAT rule for every device on site that using a STUN configuration to the 3CX server?
Yes, each phone should have a NAT rule pointing the SIP and RTP ports to the local IP of the phone.
 
Worth pointing out that you don't need to do any NAT config when you use a session border controller.

Not only does the SBC make your phones all PNP capable (no pre-config required - just plug them in), it also transports the communications over the 3CX tunnel on (default) port 5090.

If you are using a PRO or ENT license, you can also configure the SBC for PBX failover - meaning, if you've set up your 3CX installation to do failover, the SBC will recognize the failover as well.

(small print on PRO failover: It's not instantaneous. PRO takes some time to update the new IP address for the 3CX FQDN. ENT is much faster for this feature)

STUN is great when you have one phone to configure at a remote site. The moment you start using multiple phones, the benefits of the SBC well outweigh the (minor) cost.
 
Last edited:
  • Like
Reactions: YiannisH_3CX
I would use an SBC. However, If you still insist, this is courtesy of Charalambos from 3CX.


  1. 1) make sure that you have a Static Public ip Address or a resolvable FQDN so in the Phone Provisioning URL there is a valid external Public/FQDN address with the port 5000/5001 open in order to get the http provisioning file.


    2) in the provisioning tab of each extension make sure that the Local SIP Port of Phone is different between the extensions that you have selected to register through STUN method and are behind the same Public ip address: (1st 5065, 2nd 5066, 3rd 5067, etc.. ) as well the Local RTP Audio Ports Start ( 1st 14000-140011, 2nd 14012-14023, 3rd 14024-14035, etc.. )


    3) please note that each phone model has specific URL format and different "Provisioning Server" field on the web Interface of the phone. For more information please check the link on our website and specificaly the section Provisioning a remote extension in STUN Mode : http://www.3cx.com/blog/docs/provisioning-a-remote-extension/


    4) Make sure that since each phone has dedicated ports, on the remote firewall you have to make a Static NAT and Static Port Forwarding to the Private ip address of each phone.


    5) Enable the PBX Delivers audio on each extension on the Management Console >> Edit extension >> Other tab.


    6) Ensure that in front of the PBX and on the remote router/firewall option SIP.ALG is disabled.


    7) As you are using Yealink phones and these are on firmware correct filware then you will need 12 RTP ports for each extension.


    Step no2 :


    1) In the Management Console each Remote STUN Extensions must have a unique Local SIP Port and Unique RTP Port range and the RTP Port range must be 10 ports (for Yealink phones 12 ports, you do not currently have it this way) per remote site. This means that if we only had Yealink phones that would be e.g.:


    - Ext A should have Local SIP Port: 5065 and RTP Port Range: 14000-14011 (12 ports)

    - Ext B should have Local SIP Port: 5066 and RTP Port Range: 14012-14023 (12 ports)

    - Ext C should have Local SIP Port: 5067 and RTP Port Range: 14024-14035 (12 ports)

    - Ext D should have Local SIP Port: 5068 and RTP Port Range: 14036-14047 (12 ports)

    - etc...


    2) Once you have done this, then on the Remote Location Router/Firewall behind which the phones are residing, you must:

    - Disable SIP ALG or any similar port remapping feature.


    - Create NAT/Port Forwarding Rules so that, as per the above example:


    --- Ports 5065 TCP/UDP and 14000-14011 UDP are forwarded to the IP of Ext A

    --- Ports 5066 TCP/UDP and 14012-14023 UDP are forwarded to the IP of Ext B

    --- Ports 5067 TCP/UDP and 14024-14035 UDP are forwarded to the IP of Ext C

    --- Ports 5068 TCP/UDP and 14036-14047 UDP are forwarded to the IP of Ext D

    --- etc...


    - This also implies that the the phones/endpoints should have Static LAN IPs assigned to them.


    3) Re provision all Phones
 
Thanks for the information above, I have all STUN devices setup in the correct. I need to have the NAT rules setup per device, which is more of a pain for sites with more than 5 phones.

The SBC is certainly a better option in these scenarios as it would require much less setup on the firewall side.

I appreciate everyone's input, it is very appreciated and gives a better understanding of the functionality
 
Pop an EdgeWater 2900E in there, $25 a month with call licencing and management portal. I use them with all of my 3CX hosted clients. They are all setup with Yealink phones and STUN. Works well. If you have an issue, you can do a packet capture from the SBC to see what is going on.
 
Why do so many people have issues with STUN and no NAT ?
I have zero NAT setup in our office, and zero audio issue with 5 phones + some soft phones.
 
Do you use a firewall at the office? If so, what kind out of curiousity?
 
Status
Not open for further replies.

Forum statistics

Threads
111,900
Messages
589,632
Members
164,767
Latest member
Aroosa