Why would a STUN phone try to reach LAN interface?

Status
Not open for further replies.

Mark Phillips

Customer
Advanced Certified
Joined
Jan 28, 2019
Messages
154
Reaction score
53
Hi All
We've been using 3CX in a LAN/Azure environment for 18 months with good results.

I've just experimented with setting up a remote STUN extension from home. I've got it working, but I'm noticing in my firewall log (pfsense) that while idle the phone is reaching out to UDP5060 on our 3CX's public IP about once every 90 seconds. However it is also trying to hit UDP5060 on our 3CX server's LAN address (which is not route-able from here - the firewall is blocking the traffic) every 2 seconds.

Is that normal? I see no reason why it should even attempt to hit the LAN address.

I'm using a Grandstream GXP1782 with 3CX v16 SP4

Thanks
Mark
 
Have you use the 3cx template to configure the phone ?
 
Last edited:
Yes, standard 3CX template. The phone was factory reset and then did its thing via RPS. Everything is good except for the problem described above.
 
Perhaps it is because, during installation, you may have used the 3CX LAN IP? Or, as above, you used a custom template.
 
There is no reference to the LAN IP in the phone's provisioning config file.
I have done a factory reset several times now and I can't imagine the ip address would be preserved through that. I'll check the phone UI to see if there is any trace of it.
 
As suspected there was no trace in the phone UI.
I did wonder if the problem was linked to the same extension being simultaneously logged in to a hot desking extension back at the office. However, after logging the extension out of the other hotdesk extn and performing another factory reset, the problem persists.
 
Hi Mark,

"it is also trying to hit UDP5060 on our 3CX server's LAN address (which is not route-able from here - the firewall is blocking the traffic) every 2 seconds"

- What did you see in the capture exactly? Registrations? Invites?

- Are you sure it is coming from your home IP? If so, are you sure the phone is sending it?

- Did you also run a capture on the phone via its GUI to confirm?
 
Hi John
I am seeing the blocked traffic on my home firewall, so yes definitely the phone sending it. I haven't run a capture yet - I am just curious how the phone even knows the 3CX server's LAN address.
 
It could potentially be a coincidence that it is sending traffic to something else, that happens to have the same private IP as your PBX.

Run a capture from the phone's interface to see what and why it is sending. This will serve as confirmation, do not rely solely on what you see on the firewall alone because that's inconclusive.
 
Hi John
Here is the capture.

SUBSCRIBE sip:[email protected]:5060 SIP/2.0
Via: SIP/2.0/UDP 95.147.x.x:63639;branch=z9hG4bK1824188706;rport
From: <sip:[email protected]>;tag=1182008611
To: <sip:[email protected]>;tag=5cf9cb5b
Call-ID: [email protected]
CSeq: 20493 SUBSCRIBE
Contact: <sip:[email protected]:63639>
Max-Forwards: 70
User-Agent: Grandstream GXP1782 1.0.1.98 000b82a2f290
Expires: 900
Supported: replaces, path, timer
Event: message-summary
Accept: application/simple-message-summary
Allow: INVITE, ACK, OPTIONS, CANCEL, BYE, SUBSCRIBE, NOTIFY, INFO, REFER, UPDATE, MESSAGE
Content-Length: 0
 
Hi Mark,

Please confirm if the following are true:

- The capture is straight from the phone's UI, not from any other source
- The Contact IP 95.147.x.x is your home
- The Subscribe IP 172.16.x.x is the private LAN address of your PBX
- You auto-provisioned it as per our guide, with no custom templates
- Your extension's provisioning tab has Direct SIP STUN already selected AND the interface in provisioning is preselected showing your FQDN x.3cx.co.uk

If any of the above are not true, please comment accordingly
 
Hi John
The capture was taken at the firewall. Below is the capture from the phone UI.
All other statements above are true.

SUBSCRIBE sip:[email protected]:5060 SIP/2.0
Via: SIP/2.0/UDP 95.147.x.x:63639;branch=z9hG4bK2016008965;rport
From: <sip:[email protected]>;tag=1676181288
To: <sip:[email protected]>;tag=370be467
Call-ID: [email protected]
CSeq: 20554 SUBSCRIBE
Contact: <sip:[email protected]:63639>
Max-Forwards: 70
User-Agent: Grandstream GXP1782 1.0.1.98 000b82a2f290
Expires: 900
Supported: replaces, path, timer
Event: message-summary
Accept: application/simple-message-summary
Allow: INVITE, ACK, OPTIONS, CANCEL, BYE, SUBSCRIBE, NOTIFY, INFO, REFER, UPDATE, MESSAGE
Content-Length: 0
 
Thanks Mark,

Please proceed to update you PBX now to V16U5, and kindly confirm that the issue has been resolved.
 
Hi John
Is it confirmed that update 5 will resolve it, or is it just a shot in the dark?
Thanks
Mark
 
It will solve it under certain scenarios, but not for all scenarios. We are aware of an issue that still exists and are planning to correct this in a future update. It does not affect your functionality, but we shall fix it regardless.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,951
Messages
589,884
Members
164,842
Latest member
abdullah.alshehri@rewaa