Solved Unable to access FQDN from external sources

Status
Not open for further replies.

JimB

Free User
Basic Certified
Joined
Jan 10, 2022
Messages
43
Reaction score
13
Sorry if this is a bit long....
I've never been able to access the FQDN from outside the LAN, but sort of sidetracked that as not being too important. Then I noted that while my mobile rang if there was a call when I was away from the place, I was unable to answer such calls, Originally thinking that was a problem with the Android app, I posted in that forum, but then it occurred to me that the mobile would ring because outgoing traffic was fine, but I couldn't answer for the same reason (whatever it is) that was blocking external access to our FQDN...... So, I'm reposting here in the hope that someone can assist (apologies if you have already read this in the Android forum.)

Answering calls on the mobile over WiFi with a local IP address on the LAN is fine, but as with the Recents not loading, answering an incoming 3CX call on the mobile over 4G while away does not work either.... You can answer, but the result is silence and the caller does not know that the call has been answered. As above, I'm thinking it's because there's no external access.

Attempting to access https://xxxxxx.3cx.uk:5001/ gets a "connection refused" error, and on the LAN we can only access it using the local IP address. nslookup does not resolve the server IP address either.

Ports are open on our router as attachment below. The firewall has a green tick, *BUT* fails the full cone NAT tests when run.

Now I suspect our rather complex setup might be the problem. Our Internet access is via a leased fibre shared with another entity, delivered to each of us via a Ubiquiti EdgeRouter 6p - one ethernet port connecting to our router, another to theirs.

So - the question is, do I need to have ports on the EdgeRouter open too? (As in, is that why the full cone NAT tests fail, and correspondingly, why we are having trouble with the Android app and can get no FQDN Access from externally?) I'd be terrified to somehow screw up their settings!! (unsure whether the NAT can be done for one ethernet port on it only, without affecting the other....)

I would point out that all the on-premise phones are working just fine, doing everything they should, incoming and outgoing calls, voicemail, etc.... just no external access to the FQDN and not able to answer calls/see Recents list on the Android app off-premises.

Sorry this is long winded, thanks for reading this far!

ports.PNG
 
Last edited:
Hi!

So - the question is, do I need to have ports on the EdgeRouter open too? (As in, is that why the full cone NAT tests fail, and correspondingly, why we are having trouble with the Android app and can get no FQDN Access from externally?) I'd be terrified to somehow screw up their settings!! (unsure whether the NAT can be done for one ethernet port on it only, without affecting the other....)
If I understand the setup correctly, the short answer is "Yes". It sounds like there is some double NATing going on here and this makes things increasingly difficult to get working correctly, especially if you don't have control over all the network equipment.

I don't know what equipment you use, e.g. do you have IP Phones? If yes, I think maybe the best and easiest thing you could do is move your 3CX installation to the Cloud, either your own or Hosted by 3CX.

Then if you have IP Phones, re-use the machine you currently have your 3CX and convert it into an SBC, that will connect with the 3CX in the Cloud.
This is ideal for you because the SBC will automatically overcome all these port issues because it doesn't need any port forwarding and will enable your Phones to work perfectly.

Now about the apps, those also won't have a problem because now they would be connecting to your 3CX which would be in the Cloud.

This is just a suggestion.

Alternatively as I said, double NAT and you would have to forward all Ports you did on your own route also on the EdgeRouter as well and hope this works.
 
Thanks for that - yes, using Snom desk IP phones, and 3CX hosted locally on a Raspberry Pi (i'd prefer to keep that setup, rather than a hosted setup)

The main problem I have, I guess, is my unfamiliarity with configuring the Ubiquiti Edgerouter.

I'm assuming when they set it up, they have configured two VLANS (one for our connection, one for the others) I'm guessing that it must be possible to open the ports I need open *only* for one VLAN, based on it's IP address. What I wouldn't want is to open ports that affected both ports!
 
Last edited:
So, having had a snoop round the settings in the Edgerouter, I can see that I can forward the required single ports to my ethernet connection, but the port ranges, I can't (unlike on my router). I assume for those, I need to set up (both??) an SNAT and DNAT part? SNAT already enabled for me I note. Bit of a learning curve, and very cautious about changing settings....
 
So, having had a snoop round the settings in the Edgerouter, I can see that I can forward the required single ports to my ethernet connection, but the port ranges, I can't (unlike on my router). I assume for those, I need to set up (both??) an SNAT and DNAT part? SNAT already enabled for me I note. Bit of a learning curve, and very cautious about changing settings....
Things get messy from here, but for the specific ports 3CX requires to operate, I think you needs to set SNAT so that it leave the Source IP/Port unchanged and not overwrite it, it's DNAT that you need to change and point it to the IP of your "own" router.

To answer your question though, yes, on the EdgeRouter you would need to forward all ports and port ranges.

[EDIT]
And just to be sure, the full range of ports you need to forward and make sure can be reached from the internet are these:
https://www.3cx.com/docs/ports/
 
  • Like
Reactions: JimB
So one the single ports that need opened, it only needs me to add a rule for each, for our ethernet port, in the Port forwarding section on the EdgeRouter?

Under NAT, there's already an SNAT entry (specifically for our port):

Source being 192.168.2.1/24 nothing under "destination" and Translation "to 185.xx.xxx.xx" which I presume to be the public address.

Do I need to change that?

To Create a DNAT rule I get this screen:

dnat.PNG

Some of that is self explanatory, but some leave me teetering on the brink of panic! LOL Any tips on what I should fill in there?

Thanks!
 
Yes, thanks, I know which ports are required (already done on our router.)
 
Solved. I had to create DNAT entries for all ports required, on the Ubiquiti EdgeRouter. Port forwarding on it was not required. I'm assuming that the DNAT entries point the data at the internal IP of our router, and it, of course, does the port forwarding.
 
  • Like
Reactions: NickD_3CX
Glad to hear you got it all sorted out!

Just make sure that that you re-run the 3CX Firewall Checker and that everything comes back green, that is the best benchmark to see if everything was done correctly.
 
Yes, I was using the firewall checker to test the entries I was making Nick, and all is green now. :)
 
  • Like
Reactions: NickD_3CX
Yes, I was using the firewall checker to test the entries I was making Nick, and all is green now. :)
Excellent!

In that case, I will go ahead an mark this thread as 'Solved'.
 
  • Like
Reactions: JimB
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet