Trunk SIP trunk incoming calls after a while

Status
Not open for further replies.

exico

Free User
Joined
Oct 13, 2016
Messages
18
Reaction score
2
So, i just replaced a Mitel phone system with 3CX.
The trunk was configured on a Fritzbox with ISDN port and connected to the Mitel and everything worked fine.
I asked the phone company to give me the sip trunk and they did. Removed it from the Fritzbox and added to 3CX. The configuration just require the server/proxy IP and port, no authentication required.
First off, i dont get a Register OK in 3cx trunk interface but just a green icon.
Calls from inside to external go fine and external to internal too but after a while external to internal do not go trough and get trunkated with no ring whatsoever. If i make a call from in to out the start working again for a while.
Firewall is PFSENSE configured ok (is not the first installation i make), 3CX is on debian with no firewall and the 3CX firewall test is all green. I dont get any errors in the 3CX logs on incoming failed calls.

I configured the keep alive in Settings / Network / Firewall to 30 secs
I also set a re-register timeout of 65000, 30, 3 to no avail
Restarting the system doesnt help. Only making a call enable incoming calls for a while
 
Hi,

First off, i dont get a Register OK in 3cx trunk interface but just a green icon.

Correct - this is an IP based trunk so there is no registration.

Calls from inside to external go fine and external to internal too but after a while external to internal do not go trough and get trunkated with no ring whatsoever.

Restarting the system doesnt help. Only making a call enable incoming calls for a while

Sounds like your firewall is closing the port of the SIP trunk after a while, and making an outgoing call "re-opens" it temporarily.

You need to take care of the firewall configuration and open all the correct ports using Full-cone NAT.
https://www.3cx.com/docs/ports/
https://www.3cx.com/docs/pfsense-firewall/

Let us know how it goes, and click the firewall icon on your 3CX dashboard to help you validate your settings.
 
I doubled checked the firewall and is configured good. 3CX firewall test is all green.

I can try with a Messagenet account that i own and its on the supported voip providers but did not have the time.

After some tests i found that something like this works and i have no idea how.

I created a "Type of Authentication" "Incoming - Inbound only" with a fake user/pass and obviously it doesnt register. I then created the inbound rule as i needed (forward to extension).
Then i created another trunk with the same settings but now with "Do not require - IP based" and i also set up the inbound rule. the Outbound rule exits via this trunk.

My guess:
This provider is not standard, 3CX and the sip provider miss some exchanges to keep alive the connection but somehow a failed registration keep it connection open for incoming calls.

It is really strange that this trunk works on a "stupid" Fritzbox with no issues and not in 3CX
 

Attachments

  • 2020_11_13_01_09_07_3CX_Phone_System_Management_Console.jpg
    2020_11_13_01_09_07_3CX_Phone_System_Management_Console.jpg
    18.1 KB · Views: 5
I created a "Type of Authentication" "Incoming - Inbound only" with a fake user/pass and obviously it doesnt register. I then created the inbound rule as i needed (forward to extension).
Then i created another trunk with the same settings but now with "Do not require - IP based" and i also set up the inbound rule. the Outbound rule exits via this trunk.
with no issues and not in 3CX

Here is a more probable explanation: The "fake" trunk simply tries to reconnect every so often, and causes the connection to remain open. This goes in line in the same way I mentioned earlier.


It is really strange that this trunk works on a "stupid" Fritzbox with no issues and not in 3CX

The FritzBox is the firewall and the SIP client at the same time under this scenario, so it knows to keep the connection open in this case without interaction by the user (pfsense is also not involved).

Again, I think it all comes down needing to open the ports correctly on your modem and the firewall. It's not too hard to do on a FritzBox, but you have to validate and make sure it has been done correctly. If your PFSENSE is behind the FritzBox then maybe you need to enable it as "Exposed Host". Search for Fritzbox DMZ and you should see the instructions on their website
 
Fritzbox is just acting as a modem at this point. It had the Exposed host active for a while before switching to 3CX and obviously the port 5060 was occupied. When i switched and removed the trunk sip on the fritzbox the port 5060 became available to pfsense and now everything is forwarded to pfsense correctly.
PFSENSE is configured correctly. I mean: ports are natted, i created the outbound rule with static port and even set the firewall optimization to conservative.

3CX firewall test is all greeen (just ran it now).

I can do more test during the weekend. I cannot disturb any further the folks that work with that phone line
 

Attachments

  • 2020-11-13 11_32_58-3CX Phone System Management Console.jpg
    2020-11-13 11_32_58-3CX Phone System Management Console.jpg
    69.6 KB · Views: 2
Sure thing, we can pick it up later at a better time.

At the moment, is the pfsense set to exposed host on the Fritz?
 
At the moment, is the pfsense set to exposed host on the Fritz?
Yes, it is.

I tried with a Messagenet account:
i removed every sip trunk, added my messagenet test account, wait and hour or so and then try to call. Sure enough it goes trough and i get greeted by the digital receptionist.
 
At this point, I would wait until the issue returns, and then run a capture on both the firewall, and the PBX.

If the invite appears on the firewall capture but doesn't appear on the PBX capture you can at least eliminate the Fritzbox and the PBX in one go.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,990
Messages
590,164
Members
164,927
Latest member
tohoken1