Solved STUN phone on same network with another 3CX server

Status
Not open for further replies.

jholbrookFTLtechnology

Silver Partner
Advanced Certified
Joined
Jun 21, 2019
Messages
59
Reaction score
4
Can you have a STUN extension that is connected to an external 3CX server on the same network as an on-premises 3CX server? what i'm trying to do is this, i have a 3CX system here with many extensions but want to take 1 phone and connect it to another 3CX server using STUN. i can get it to provision but the phone always says no service. i've forwarded ports to the STUN phone (5065, 14000-14019) and those same ports to the remote 3CX server and created firewall rules to allow access on both ends.

is it possible and if so what am i missing here? there is a curious entry in the logs on the remote server (There's another STUN server that resolves to the same IP:)
 
You only need to setup the port forwarding on the firewall protecting the stun phone.

On the firewall protecting the 3cx server, you only need to setup the default 3cx ports - nothing extra is required for the stun phone.

Have you unticked, under options for the extension - ‘allow stun or remote’ (cannot remember the exact text)

Also check your IP blacklist
 
What phone are you trying to provision ?
 
You only need to setup the port forwarding on the firewall protecting the stun phone.

On the firewall protecting the 3cx server, you only need to setup the default 3cx ports - nothing extra is required for the stun phone.

Have you unticked, under options for the extension - ‘allow stun or remote’ (cannot remember the exact text)

Also check your IP blacklist

yes, i have unchecked the option that prevents it from connecting outside the LAN.
 
i just reset the phone and went through the process again, same result. the phone provisions but says no service and trying to make a phone call says invalid.
 
to add a little more to this, the phone has the correct phone book, it just will not make a call and says that it has no service.
 
on the remote firewall ports 5065 and 14000-14019 both TCP and UDP are forwarded to the phone which has a static reservation. the forwarding is probably overkill but i'm trying everything.
 
So something doesn't jive here. If it provisions, then that means you aren't blacklisted and you don't have an SSL problem. If you unchecked 'Disallow use from outside LAN' then there should be nothing stopping it from registering. Was this phone ever used on the local PBX? Can you web into the phone and make sure the provisioning path and account info are what you expect them to be?
 
  • Like
Reactions: eddv123
it was used on the local PBX but i factory reset it. it's provisioning correctly but will not show that it's online. i suspect that some of the NAT policy for the local PBX is interfering with it from working. i plan to test it tomorrow on a separate network and i'm willing to bet it will work as it's supposed to.
 
Well if was an existing phone before v15 then it's possible you still have a flat file config on the local PBX that it is picking up via option 66. You see anything in the local PBX logs regarding registration attempts from that phone? Otherwise you might be right about the NAT stuff
 
I didn't look on the local PBX but will do that tomorrow, the phone has only ever been on the current version of 3cx.
 
Does the "other" 3CX server, that you are trying to register this set to, show any attempt (but rejection), in the Activity Log? Even if the local router were blocking incoming, to that set, you should see some attempt in the log unless the set is not configured with the correct server destination.
 
It's worth running a capture on the external 3CX system to see if this STUN extension actually attempts to register on it, and then see where you go from there.

Might also be worth checking your firewall, to see if you have any policy that affects the SIP port (I imagine you use 5060 for both 3CX servers)

Edit: Also ensure the FW is the latest supported by 3CX before doing the above
 
i had a rule that only allowed traffic on 5060 from certain addresses, i disabled that restriction but the phone would not register. i wiped the phone and re-registered it on the local PBX then connected to a 4g router and changed the provisioning link to the stun address of the local PBX and the phone was able to register and make calls correctly.

i will try again on the remote PBX later today. both systems are set up identically with the only difference is the remote PBX is on a dynamic address but that shouldn't matter as i am using the FQDN and can interact with the PBX fully from where i'm at.
 
Ah yes that would make sense then, the traffic was probably blocked as a result. Provisioning worked originally because that uses the HTTPS port, hence you were provisioned but not registering as soon as your phone tried to send traffic to 5060.

An alternative would be to use a different SIP port than 5060 on the remote PBX so you can keep your local network rule (requires reinstalling the remote PBX as the SIP port cannot be modified after installation).
 
got it, it was a firewall issue. i have 1 outbound NAT rule for all 3cx service rules and 1 inbound NAT rule for them as well that lumped all services together. i however had 2 firewall access rules. 1 for SIP ports and the second for the rest. the intention was to limit inbound access from only my sip provider, i had disabled that restriction yesterday but it was still failing. i disabled the SIP access rule and added the services to the other rule that allowed all the rest of the services to traverse and the phone immediately registered and now works, even on the local lan.

i re-ran the firewall checker and when it failed full-cone on 5060 (on remote PBX) it led me to the above.
 
Glad to hear it was resolved then, good troubleshooting!
 
Status
Not open for further replies.

Forum statistics

Threads
111,928
Messages
589,778
Members
164,800
Latest member
JensVoss