We use a non-standard SIP port. Options for getting a Trunk on 5060 working?

Status
Not open for further replies.

shak

Customer
Joined
Oct 3, 2020
Messages
19
Reaction score
2
Hi,

We use a non-standard SIP port for some obscurity and everything's been fine so far.

We're setting up a trunk with a new service provider over a dedicated connection that doesn't require Registration.

HOWEVER, their incoming SIP messages all land on 5060, unless they're replies.

We have a meeting this Friday and we'll ask if they can change the port on their side, for us.

If that isn't possible:

Do we have any options aside from changing 3CX's port (backing up, reinstalling, and so on) and then changing all our non-3CX-client endpoints that don't have provisioning templates?

Thanks
 
If their trunk does not require registration, then how are they to know which port to send an invite to (as it's not 5060), unless you tell them, and they can accommodate you ?

If they can't, I'm not certain what you can do, other than changing the port back to 5060, on 3CX, or finding another provider. I've not seen having a different SIP listening port, on a per trunk basis.
 
Last edited:
  • Like
Reactions: shak
As @leejor said, you cannot change the SIP Port without uninstalling and re-installing and you cannot use a separate SIP Port per SIP Trunk.

I don't know which SIP Provider you are currently using but if you are considering switching I would recommend one of the 3CX Supported ones for a more streamlined and trouble-free experience.: https://www.3cx.com/partners/voip-providers/
 
  • Like
Reactions: shak
Hi,

We use a non-standard SIP port for some obscurity and everything's been fine so far.

We're setting up a trunk with a new service provider over a dedicated connection that doesn't require Registration.

HOWEVER, their incoming SIP messages all land on 5060, unless they're replies.

We have a meeting this Friday and we'll ask if they can change the port on their side, for us.

If that isn't possible:

Do we have any options aside from changing 3CX's port (backing up, reinstalling, and so on) and then changing all our non-3CX-client endpoints that don't have provisioning templates?

Thanks
If you use the mobile apps and SBC only, the 5060 port can be locked down to your SIP provider instead.
 
  • Like
Reactions: shak
  • Like
Reactions: shak
I think what he means is that his SIP provider doesn't allow to change SIP ports. In this case, I would recommend reinstalling 3CX (create backup and when you restore it will ask what SIP port to use again) or use a carrier grade SBC. https://ribboncommunications.com/pr.../session-border-controllers-service-providers
The reason why they wanted to use another port than 5060 is to lock it down to the provider's IP for security.

If they use SBCs and mobile/desktop apps, the port 5060 isn't used by those so the customer can freely lock 5060 down to the provider. If they have STUN phones or local LAN phones, then the port needs to stay opened, in which case, they would need a carrier-grade SBC anyway since the provider and the LAN/STUN phones use the same 5060 port.
 
  • Like
Reactions: chance-wmt and shak
Thanks for the replies, everyone.

We'll find out whether the SIP provider will be able to change the port tomorrow.

Was just trying to gather all the options so that we know what we're in for, in case.

We don't currently have a separate SBC. We have our PSTN trunks on separate, dedicated, links (not our Internet WAN port). We do have our Windows-3CX-App/Web/Mobile users. Does this mean that we don't need to expose (the equivalent of) 5060 / 5061 to the WAN? Went through this page: https://www.3cx.com/docs/ports/ and, in addition to @ConceptsWeb 's contribution, that's the impression I get. If that is so, then I can simply drop the port forward in our router, even regardless of what happens with our current SIP Trunk matter.

Thanks
 
Thanks for the replies, everyone.

We'll find out whether the SIP provider will be able to change the port tomorrow.

Was just trying to gather all the options so that we know what we're in for, in case.

We don't currently have a separate SBC. We have our PSTN trunks on separate, dedicated, links (not our Internet WAN port). We do have our Windows-3CX-App/Web/Mobile users. Does this mean that we don't need to expose (the equivalent of) 5060 / 5061 to the WAN? Went through this page: https://www.3cx.com/docs/ports/ and, in addition to @ConceptsWeb 's contribution, that's the impression I get. If that is so, then I can simply drop the port forward in our router, even regardless of what happens with our current SIP Trunk matter.

Thanks
If you are not using hard/IP phones over the WAN in STUN mode (Direct SIP) and your SIP service is also not coming from the WAN you don't need 5060/5061 open at all. SBC and Apps use 5090 and webclient is over 5001/443 (depending on your setup)
 
If you are not using hard/IP phones over the WAN in STUN mode (Direct SIP) and your SIP service is also not coming from the WAN you don't need 5060/5061 open at all. SBC and Apps use 5090 and webclient is over 5001/443 (depending on your setup)

That's excellent! I'm going to drop the port forward ASAP.

I still hope we don't need to change the regular port. Otherwise we're up for a big job.

We're going from the largest PSTN telco in our country to the second largest. The second isn't listed as supported on 3CX's site, but they said in pre-sales that they can work with 3CX.
 
@shak
If you are not using hard/IP phones over the WAN in STUN mode (Direct SIP) and your SIP service is also not coming from the WAN you don't need 5060/5061 open at all. SBC and Apps use 5090 and webclient is over 5001/443 (depending on your setup)
This is absolutely true, just bear in mind that the Firewall checker will not successfully pass with the SIP Port locked down so I'd recommend running it before restricting the traffic. This will also affect 3CX Bridges that are not configured to use the 3CX Tunnel.
 
Just got word back... 95% sure that they can't / won't change the port they use for our trunk. They're just doing a final check with someone else before confirming that answer. Not holding my breath.

We're due for the v18 upgrade, so here goes nothing. May be time to implement a template or develop some other method for the 50 or so manually provisioned devices.

Thanks again.

shak
 
  • Like
Reactions: ChrisC_3CX
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,284
Members
164,662
Latest member
DejanMDS