STUN

Status
Not open for further replies.

ITC Telecom

Gold Partner
Joined
Mar 28, 2019
Messages
23
Reaction score
1
I've heard from other companies that install 3CX that using STUN for remote phones only works for up to 10-12 phones and anything over that was advised that a SBC would be needed. Any truth to this?
 
In fact, for under 5 phones, STUN is ok as long as you adjust the local SIP and RTP ports on each one so they don't collide.

Beyond that, use an SBC. You gain PnP support as a bonus.
 
Using stun can handle as many phones as you need but the management becomes a pain.

Each phone needs a fixed IP address, different blocks of rtp ports, different sip port. You need to setup port forwarding for each phone (using the correct ports) on your route

Using a sbc server makes your life so much easy
 
I have dealt with sites with in the region of up to 50 STUN phones on one site so it is not so much there is a limit, just as previously specified the management becomes an issue. I have known issues for port clashing even as low as 3/4 STUN phones on the same site.

For multiple STUN endpoints we would need:
  • Each endpoint on its own statically assigned IP (whether it be static or via DHCP >> MAC assignment).
  • SIP ALG, SIP Helper or Deep Packet Inspection needs to be disabled on the firewall – can be different names based on the vendor (and can be GUI or CLI command).
  • Ports forwarding and port allocation needs to be configured properly.
Each phone needs to have a unique - specific SIP and RTP/media ports – downloading the extensions CSV file from 3CX can be used as a guideline to see what the advised STUN ports are configured on your extensions.

For the ports, SIP is incremented normally by x2 and RTP by X12 for Yealink phones. For example:

Ext - 1: 5062 & 14000 - 14011
Ext - 2: 5064 & 14012 - 14023
Ext - 3: 5066 & 14024 - 14035

I still do not recommend or support this setup and would always recommend a VPN or SBC as already suggested here.
 
Each endpoint on its own statically assigned IP (whether it be static or via DHCP >> MAC assignment).

Why???? I never did that and never needed it.
 
Why???? I never did that and never needed it.

So that the port forwarding configure on the router / firewall is pointing to the correct phone.

If the phone does not have a fixed IP address , port forwarding setup will not work if the phone IP address changes.
 
So that the port forwarding configure on the router / firewall is pointing to the correct phone.

If the phone does not have a fixed IP address , port forwarding setup will not work if the phone IP address changes.

I did not forward any port in STUN. This just causes issues with ghosts calls.

I have 3 phones running in STUN at a remote office and we have no issues at all. All we did was adjust SIP/RTP ports and disable SIP ALG in the firewall.
 
I have 3 phones running in STUN at a remote office and we have no issues at all. All we did was adjust SIP/RTP ports and disable SIP ALG in the firewall.

Well you are one of the lucky ones in this case although 3 phones are quite low, the SIP/RTP ports in 3CX >> Extension >> Provisioning: doesn't actually do much, they are more of a guideline for how to keep your ports in in-cremation.
 
I did not forward any port in STUN. This just causes issues with ghosts calls.

I have 3 phones running in STUN at a remote office and we have no issues at all. All we did was adjust SIP/RTP ports and disable SIP ALG in the firewall.

3CX supported setup is to configure stun phones is to setup port forwarding. - see slide 6
https://www.3cx.com/3cxacademy/videos/intermediate/configuring-remote-extensions/

Also check out post #5 -
https://www.3cx.com/community/threa...etgear-nighthawk-x4s-d7800.54620/#post-225296
 
Well I guess it depends on the situation. I never had issues, but some have.

This is why I use a SBC for sites with 5 or more phones.
 
thanks for the reply! so are you saying that STUN is ok for 5 phones or under from a management perspective or from a functional perspective? and if from a functional perspective, what doesn't work right specifically?

In fact, for under 5 phones, STUN is ok as long as you adjust the local SIP and RTP ports on each one so they don't collide.

Beyond that, use an SBC. You gain PnP support as a bonus.
 
from a management perspective or from a functional perspective

I'd say a bit of both:

-> Management: more than 5 phones in STUN (at the same site of course) is a pain to manage because of the Local SIP/RTP Ports that needs to be adjusted for each one. Then when you add a new phone, you need to look back at which ports are used or remember. Also, you may need to open some firewall ports, which is another thing then to manage.

-> Functional: while you may manage to get 10-15 phones (or more) working in STUN, eventually you'll run out of ports. That many phones can also start to cause audio issues when packets are misdirected in the router because of so many SIP/RTP ports (I had issues with that in the past, I would receive a call on a STUN phone and another one would become one-way audio instantly).

From both perspective, the SBC fixes a lot of problems. The management issue is cut in half since the SBC takes care of the ports and only uses the tunnel to talk with the PBX (which is also more secure than STUN, specially since 3CX doesn't support SIPS/SRTP yet). You get PnP support as a bonus, so adding new phones is easy, and you get more stable audio when speaking from remote-to-remote since the SBC keeps the audio local, not the STUN mode.

Be aware that a SBC has a limit of devices/BLFs that can be supported. HOWEVER, you can install multiple SBCs per-site to account for that.

Hope that helps :)
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,924
Messages
589,756
Members
164,796
Latest member
Dame24