leejor, thanks for providing your thoughts again. I just ran the firewall checker again to make sure all ports can be reached. All seems fine with that:
3CX Firewall Checker, v1.0. Copyright (C) 3CX Ltd. All rights reserved.
<17:07:00>: Phase 1, checking servers connection, please wait...
<17:07:00>: Stun Checker service is reachable. Phase 1 check passed.
<17:07:00>: Phase 2a, Check Port Forwarding to UDP SIP port, please wait...
<17:07:05>: UDP SIP Port is set to 5060. Response received correctly with no translation. Phase 2a check passed.
<17:07:05>: Phase 2b. Check Port Forwarding to TCP SIP port, please wait...
<17:07:10>: TCP SIP Port is set to 5060. Response received correctly with no translation. Phase 2b check passed.
<17:07:10>: Phase 3. Check Port Forwarding to TCP Tunnel port, please wait...
<17:07:14>: TCP TUNNEL Port is set to 5090. Response received correctly with no translation. Phase 3 check passed.
<17:07:14>: Phase 4. Check Port Forwarding to RTP external port range, please wait...
<17:07:20>: UDP RTP Port 9000. Response received correctly with no translation. Phase 4-01 check passed.
<17:07:24>: UDP RTP Port 9001. Response received correctly with no translation. Phase 4-02 check passed.
... removed for readability (all passed) ...
<17:11:01>: UDP RTP Port 9049. Response received correctly with no translation. Phase 4-50 check passed.
<17:11:05>: UDP RTP Port 9050. Response received correctly with no translation. Phase 4-51 check passed.
Application exit code is 0
To draw an idea of the setup of the 3CX installation I'm running:
- The 3CX server is equipped with two NICs. One facing the internal network and one being directly bound to the internet through a public IPv4 and public IPv6 address. It uses the standard Windows firewall to only allow communication through the 3CX ports from the internet.
- One remote network connects via a permanent VPN connection over IPv6 using Linksys SPA3102 and Linksys PAP2T devices to the internal network on which the 3CX server resides. These devices have private IPv4 addresses and use the internal IPv4 address of the 3CX server to communicate with it using the IPv4 protocol.
- The extension causing trouble is located remotely from the 3CX server on a home ADSL connection with a fixed IPv4 address. It connects directly through the internet using IPv4, without a VPN, to the internet facing NIC of the 3CX server.
I have not opened up any ports on the firewall of the Zyxel device. I assumed since it is also the ADSL modem/firewall it will place it's VoIP capabilities outside of its own firewall. I confirmed this assumption for myself by also not having to open any ports to use the VoIP service delivered by the ISP of the ADSL connection and by being able to register and open a vocal contact with the 3CX server.
The firmware is the latest, although it dates back from August 2008, there is no newer firmware available unfortunately.
I have also tried a factory reset. As the matter of fact, it occurred to me once that the device got into a reboot loop because after rebooting it would register with 3CX, directly crash and reboot again, register, crash and reboot again, etc. The only way to stop this from happening was by disconnecting the DSL line, having the device boot up, factory reset and plug back in the DSL line. So no avail through this method.
I think we can point it down to being an error in Zyxels firmware. Strange thing is that it never occurs with the VoIP of the ISP though. So 3CX must send out some unique command which causes the Zyxel to crash immediately. I will try to see if I can get Zyxel to analyze the situation, but I guess they won't. I'll try to get my hands on another Linksys PAP2T or SPA3102 to see if that will work in this setup.
If any more thoughts or ideas come up, please do let me know.
Thanks!