Teams Integration not connecting, any help would be appreciated

hhc-it

Customer
Joined
Sep 24, 2024
Messages
2
Reaction score
0
Hi All,

We are having some problems trying to get the 3cx to integrate with Teams.

Our setup has
  • An Enterprise licence with 16 SC's
  • Teams standard licences (currently trial) applied to the users
  • Custom sub domain for teams setup (teams.domain.com)
  • Certificate for that custom domain from DigiCert as preferred by Microsoft (it is a subdomain of teams.<main domain> not a wildcard)
  • The teams integration is active with port 5062 open on the firewall for the server.
  • The certificates are installed on the teams integration.
  • I can nmap the server port 5062 on the server and see that the correct certificate is being presented.
    • command: nmap --script ssl-cert -p 5062 domain -Pn
    • output:
    • PORT STATE SERVICE
      5062/tcp open na-localise
      | ssl-cert: Subject: commonName=teams.domain.com/organizationName=<ORG NAME>/stateOrProvinceName=Western Australia/countryName=AU
      | Subject Alternative Name: DNS:teams.domain.com
      | Issuer: commonName=DigiCert EV RSA CA G2/organizationName=DigiCert Inc/countryName=US
      | Public Key type: rsa
      | Public Key bits: 2048
      | Signature Algorithm: sha256WithRSAEncryption
      | Not valid before: 2024-08-13T00:00:00
      | Not valid after: 2025-08-13T23:59:59
      | MD5: 9fcc 7395 5aa0 720d af8e a037 426b c79f
      |_SHA-1: 62c2 c53d 1ac1 b0cc 6ce6 083b ae95 7cdd 9865 3903
  • The key length is correct.
  • I have anonymised the SAN in the above text but that is also correct on the cert.
  • Dial plan and users script has been run on MSOnline
  • The SBC has been created along with dial plans etc
  • The 3CX activity log relating to "teams" shows
    • 09/24/2024 11:09:53.774 PMExtn:107 has specified Teams number: <MAIN PHONE NUMBER>;ext=107
      09/24/2024 11:09:53.774 PMAdded Teams mapping <MAIN PHONE NUMBER>;ext=107 <-> 107
      09/24/2024 11:09:53.769 PMResolving Teams FQDN sip.pstnhub.microsoft.com
      09/24/2024 11:09:53.756 PMCreated transport for Teams SBC: 0.0.0.0:5062/TLS fk=0 tgt=
Additional info.
  • 3CX is a self hosted debian machine.
  • Server is behind a Sophos firewall.
  • All firewall/NAT rules are working.
  • Can access the web platform on the 3CX (port 5001) not issues.

Issues:
  • The voice directing routing on o365 (Teams) shows that the SBC has never connected.
  • I left for 24 hours as recommended but still won't connect.
  • The TLS Connectivity Status says never connected
  • The SIP options says the following: "The Session Border Controller exists in our database (your administrator created it using the command New-CSOnlinePSTNGateway). It's configured to send SIP options but we never saw SIP options coming back from this SBC".

Whatever I try I just can't get it to connect. Are there any logs on the Microsoft side that I can refer to potentially?

Any help would be much appreciated.

Regards
Charlie
 
Last edited:
Have you confirmed that the port 5062 is accessible from the outside? Aka opened in the firewall, not just in the VM.
 
Yes all ports required are NAT'd and available from the outside.
 
You have added a new domain in Azure (e.g.: teams.domain.com).
Have you created a new user with this domain and assigned them a Direct Routing license?
(You can assign it to another user later.)

Adding an alias to a user is not sufficient.
Please create a temporary new user in Azure with the new domain directly (without assigning them an alias).

Test your Teams integration with this user, and once it's working, you can delete the temporary user and assign the license to another user.

Then, execute the "users script" generated by 3CX. Everything should work.
 
Please create a temporary new user in Azure with the new domain directly (without assigning them an alias).
I found this solution on the Microsoft forums. It seems that creating a user with this subdomain triggers something on Microsoft's end for some unclear reason. Now, this is the solution I use every time, and it works flawlessly.
 
  • Like
Reactions: Evolute IT
Have you created a new user with this domain and assigned them a Direct Routing license?

Adding an alias to a user is not sufficient.
Hey Guillaume,

We have multiple domains, so if the FQDN is teams.domain.com, the primary user account should be [email protected] and the Direct Routing license should be assigned to them and Microsoft Phone Standard add-on is not sufficient to make the things work. Please advise if I understand that correctly.
 
Last edited:

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK