TIP: How to get 1 or more DIRECT SIP(STUN) phones working through Cheap/ISP Firewalls

Status
Not open for further replies.

BrenttG

Platinum Partner
Advanced Certified
Joined
Nov 17, 2017
Messages
912
Reaction score
586
This is a rudimentarily simple trick we have been using to punch phones through many of the cheap home use Modem/WiFi/Router/Firewall Combo devices, including those provided by many carriers for DSL and Cable connections at employees homes, etc... This trick does not always work, but at this point i will say it works 80% of the time...

  1. Edit the extension settings in 3CX > Extensions > (Problem Extension) > Phone Provisioning, Set Local SIP Port, to a value of 45125, if more then one phone is at this location, stagger them by 1.
  2. Ensure the Local RTP Ports are at or above 14000, and again if multiple phones are present, stagger them by 20 per 3CX's docs
  3. Go to Options Tab and Enable PBX Delivers Audio if it is not already, for all phones at this site.
  4. Click OK to save the changes, and re-provision the phones, either from the phones tab, or manually using auto-provisioning.
If it still doesn't work, sometimes this is because the attempt to re-provision from the phones tab didn't work, factory reset the phone, and auto provision it manually from the web interface of the phone itself.

If you can now establish a call, but have either 1 way audio, or no audio, you can try bringing the RTP ports up into the high range as well, perhaps starting around 46000 or 47000, just being careful not to overlap them with the SIP ports. However 80% of the time when having to do this, the audio ports work just fine on the 14000s.

We have only ever tested this with Yealink Phones, so we cannot confirm or deny how this works with other models, but based on the networking standards involved, Vendor should be irrelevant.

If it still doesn't work then you have a very screwy firewall/router and/or ISP....

Be sure to Like or Love if this helps you out, it has saved us Many times now.

Why does this work you ask?
While most Enterprise Class firewalls respect port rules equally, many low end combo units with low budget firmware commonly sold for home use, or provided by Cable/DSL ISPs seem to block or otherwise cause issues with lower range port numbers, but will allow ports in the Ephemeral Range a bit more freely, and without transforming them in many cases. Reasons and such will vary between the various vendors, thought many of them are also based on the same sources, and are actually just re-branded from the same MFGs.

But the Ephemeral Range is 1025-65535, so the ports are already in this range?!?!
While Microsoft has sometimes in the past said anything over 1025 ""technically"" being ephemeral, they are wrong like usual, Most software and OS's actually refer to the ephemeral port ranges being either 49152-65535(IANA), or 32768-61000(Linux), Now 99% of those cheap little combo DSL/Cable WiFi/Router Combo units are running linux kernels, so working from my past experiences with these pieces of garbage, and observing the Ephemeral port range that many linux kernels use, I did a bunch of testing and that is how i discovered all of this.... Microsoft too got wiser and now follows the IANA standard. Proving even they can do something right.
 
Last edited:
Firewalls this has helped with?
Arris, Asus, Motorola, Actiontec, Zyxel, Cisco(Cable Modems), Technicolor, Netgear, D-Link, Hawking, Linksys, 2Wire, TP-Link....
 
just had this solve the same problem on a Cox provided Arris All in one modem at an executives home, prior to applying this fix, his calls would end at the 30 second mark.
 
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,818
Members
164,811
Latest member
aurorasigntrtechitnet