FIREWALL 3CX CLOUD

riccardofrigerio

Trainee Partner
Basic Certified
Registrato
19 Luglio 2019
Messaggi
1
Ciao a tutti, il mio problema è molto semplice.

Ho un PBX 3CX in cloud sul quale firewall abbiamo aperto TUTTE le porte verso il provider VoIP. Gli interni si registrano al 3CX tramite SBC il quale risiede nella stessa LAN dei telefoni. Abbiamo anche aperto tutte le porte dal 3CX verso l'indirizzo pubblico (WAN) della LAN dove risiedono interni ed SBC, nonchè la porta 5090 sul router dove risiede l'SBC.
Il centralino sembra funzionare correttamente nella sua interezza, salvo alcuni saltuari problemi di audio (scomparsa di audio da un certo punto nella chiamata, mancanza di audio mono o bidirezionale).

Il firewall check integrato riporta questo:


  • resolving 'stun-eu.3cx.com'... done
  • resolving 'stun2.3cx.com'... done
  • resolving 'stun3.3cx.com'... done
  • resolving 'sip-alg-detector.3cx.com'... done
  • testing 3CX SIP Server... failed (How to resolve?)
    • stopping service... done
    • detecting SIP ALG... not detected
    • testing port 5060... not reachable (How to resolve?)
    • starting service... done
  • testing 3CX Tunneling Proxy... failed (How to resolve?)
    • stopping service... done
    • testing port 5090... not reachable (How to resolve?)
    • starting service... done
  • testing 3CX Media Server... failed (How to resolve?)
    • stopping service... done
    • testing ports [9000..9398]... failed (How to resolve?)
Tutti test delle porte da 9000 a 10098 falliscono.

Ho inoltre scaricato il client per il firewall checking da remoto, e il risultato è questo:

Start test, v.1.0.4
Extension '321' has been unregistered 408
3CX Phone System Server is unreachable using UDP transport. (408 Request timeout)
Trying to use TCP transport.
Extension 321 is registered
Calling *777
Connection with *777 established
Audio port is 9690
ERROR: Echo test - audio was not received from PBX
Possible causes:
1. Firewall(NAT) is blocking audio delivery when call is initiated by remote devices
2. Audio Ports are not port forwarded correctly
3. Network failure
WARN: there were no RTP packets received!
Possible causes:
1.SIP ALG or a SIP Proxy has been detected between this computer/network and the target 3CX PhoneSystem. This will cause problems.
Check with the firewall or SIP ALG/Proxy documentation on how to resolve this problem. In most cases SIP ALG should be disabled.
2.Your 3CX PhoneSysem Server might have a Dynamic Public IP address. 3CX PhoneSystem MUST have a Static Public IP.
(A Public IP Address that does not change)
3.You might be using a service like Dyn Dns and the DNS Record has been updated.
Dyn Dns is not supported and you need to configure your DNS correctly if you plan to use 3CX Phone System with an FQDN.
4.3CX PhoneSystem's border firewall might not have the correct Port Forwarding rules configured.
Please launch 3CX Management Console, go to Settings > Network> Firweall Checker> Run Firewall checker.
This will give you an exact list of what ports you would need to open. If the test fails, you would need to login to your firewall and open / port forward the required ports.
Audio port is 9690
Calling *888
Waiting for Callback from *888
Answering call from *888
Connection with *888 established
Audio port is 9694
ERROR: Callback test - audio was not received from PBX
Possible causes:
1. Firewall(NAT) is blocking audio delivery when call is addressed to remote devices
2. Audio Ports are not port forwarded correctly
3. Network failure
WARN: there were no RTP packets received!
Possible causes:
1.SIP ALG or a SIP Proxy has been detected between this computer/network and the target 3CX PhoneSystem. This will cause problems.
Check with the firewall or SIP ALG/Proxy documentation on how to resolve this problem. In most cases SIP ALG should be disabled.
2.Your 3CX PhoneSysem Server might have a Dynamic Public IP address. 3CX PhoneSystem MUST have a Static Public IP.
(A Public IP Address that does not change)
3.You might be using a service like Dyn Dns and the DNS Record has been updated.
Dyn Dns is not supported and you need to configure your DNS correctly if you plan to use 3CX Phone System with an FQDN.
4.3CX PhoneSystem's border firewall might not have the correct Port Forwarding rules configured.
Please launch 3CX Management Console, go to Settings > Network> Firweall Checker> Run Firewall checker.
This will give you an exact list of what ports you would need to open. If the test fails, you would need to login to your firewall and open / port forward the required ports.
Audio port is 9694

Ora, mi sembra di capire che ci sia qualche problema senz'altro a livello di porte. Però, mi sembra naturale che ci sia, nel senso che noi le porte le abbiamo aperte verso il nostro provider, non verso i server di 3CX, quindi è logico che quest'ultimo le trovi chiuse e abbia problemi. Di contro, però, non dovrebbe averli la comunicazione SIP e RTP verso il provider.
Non riesco dunque a capire la natura del ragionamento del firewall check e se è necessario aprire le porte (anche solo quelle specificate dai tutorial) ma verso il mondo, e non solo verso il provider.

Spero che qualcuno possa essermi d'aiuto, grazie mille.
 
Ciao,
il firewall check è pensato per essere lanciato a verifica dell'inoltro corretto delle porte verso la macchina in rete locale e questo è storicamente un ostacolo nelle installazioni on-premise.
Nella pratica, simula una connessione SIP verso 3 distinti server 3CX.
Se hai un centralino in cloude hai creato contestualmente delle regole ACL, è naturale che nel tuo caso fallisca.
Di solito consiglio di fare in due passaggi: aprire le porte verso tutti e verificare che il fw check venga superato. Una volta ottenuto questo risultato ,limitare l'apertura ai soli IP necessari.
 

Inizia con 3CX – Admin

Forum statistics

Discussioni
44.663
Messaggi
233.427
Membri
78.448
Ultimo Iscritto
ProfIT Solution Pühringe