Solved V20: No Admin Console for "System Owner" extension

Status
Not open for further replies.

aragone

SMB User
Joined
Nov 2, 2022
Messages
14
Reaction score
2
Hello, we just did a fresh install and restored from backup from V18 to V20. SIP trunks, app connections, and calls / text work, but despite logging into every extension we have, there is NO section in the new Web UI for the Admin Console (and of course we are focused the most on the extension that the web setup wizard mentions should be the main user to login with).

Is there a direct URL to force navigate to it?
Can I reset user permissions and/or force create a new user in the CLI that has admin access?
Is there a database setting to tweak somewhere?
 
Have you ensured that you are accessing the PBX with the System Owner extension?
 
Yes, and like mentioned we logged into EVERY extension on the system for good measure to double check. It almost seems like a setting didn't transfer properly.

It seems the bottom left SHOULD turn into an "Admin Gear" icon, but we only see "Apps Box" icons.
 
Where there any console restrictions configured in the PBX prior the update?
 
Thanks @SweetAction for the URL - navigating to it direct redirects me back to `/people`.

I went into the old v18 system before upgrade and confirmed the extension (my user) that is indeed a System Owner, but the new v20 system isn't recognizing that.

How can review and update settings in the new v20 system to restore access? I'm very comfortable on the command line and don't mind doing that.
 
Where there any console restrictions configured in the PBX prior the update?
You didn't answer this...try from the 3CX server's LAN if it's truly on premises and not hosted somewhere. Admin isn't accessible if it's blocked by IP restrictions.
 
Where there any console restrictions configured in the PBX prior the update?
I'm not sure what those are, so think that's unlikely. I can login to the old system to check ... have docs or a config section I should look at?
 
Security/Console Restrictions.

"This allows you to restrict which IP addresses can connect to the 3CX Management Console. By default the MC is allowed from everywhere.

[ ] Allow Access from everywhere
[x] Allow Access from specific IP Addresses"
 
I think I found the Console Restrictions config: it looks to be open to all RFC1918 space and v6 link-local.

A quick tcpdump (when hitting the Web UI with the FQDN) does look to be a v4 public IP.

I hit the private IP with a forced Host header and it looks to have `Admin` and `Apps` available as options now, so I'm going to poke around here and update Console Restrictions to see what I can get working without Header modification shenanigans.

As an aside, does the web portal support a Reverse Proxy yet with XFF headers or similar? I'd really love to throw mTLS or some other restrictions and logging onto the interface, especially now that the Admin Console is exposed to the Internet.
 
Circling back here: I was able to get access via the normal FQDN by updating the Console Restrictions IP address list. Everything looks to be working now.

Thanks everyone for the quick troubleshooting ideas.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,080
Members
164,899
Latest member
mazet