To ensure that your 3CX server works correctly with Internetport, you need to open specific ports in both the firewall and the router. This guide provides a detailed port list for SIP, RTP, tunnel, and web admin, as well as instructions on how to configure NAT and disable SIP ALG.

Port Overview: SIP, RTP, Tunnel, Web Admin

For 3CX to communicate with Internetport, several ports need to be open. Here is an overview of the most important ones:

  • SIP (Session Initiation Protocol): Port 5060 UDP/TCP
  • RTP (Real-time Transport Protocol): Port range 10000-20000 UDP
  • Tunnel: Port 443 TCP for secure communication
  • Web Admin: Port 5090 TCP for access to the 3CX admin page

Incoming Rules That Must Be Open (Port List)

To receive calls and data from Internetport, you need to configure the following incoming ports in your router:

  1. Step 1: Open SIP Port

    Open UDP/TCP port 5060 to allow SIP communication. This is the primary communication port for calls and messages.

  2. Step 2: Open RTP Port Range

    Configure UDP port range 10000-20000 for RTP streams. This port list is used to transfer voice data in real-time.

  3. Step 3: Open Tunnel Port

    For secure communication, open TCP port 443, which is used for tunnel communication to Internetport's SIP server.

  4. Step 4: Open Web Admin Port

    TCP port 5090 should be open to provide access to the 3CX admin page, which is useful for management and configuration.

Outgoing Rules to Internetport SIP Server

To ensure outgoing communication to Internetport's SIP server, you need to configure the following outgoing ports:

  1. Step 1: Configure UDP/TCP Port 5060

    Allow outgoing traffic on UDP/TCP port 5060 to initiate SIP sessions to Internetport's SIP server.

  2. Step 2: Configure RTP Port Range

    Allow outgoing UDP traffic in the port range 10000-20000 to send voice data to Internetport's SIP server.

  3. Step 3: Configure Tunnel Port

    Allow outgoing TCP traffic on port 443 for secure communication with Internetport's SIP server via a tunnel.

SIP ALG - Why It Causes Problems and How to Disable It

SIP Application Layer Gateway (ALG) can disrupt 3CX communication by manipulating SIP messages. Therefore, it is recommended to disable SIP ALG in your router:

  1. Step 1: Log In to Router Admin

    Go to your router's admin interface by entering the IP address in a web browser.

  2. Step 2: Find SIP ALG Settings

    Locate the SIP ALG settings, which are often found under advanced network settings or QoS (Quality of Service).

  3. Step 3: Disable SIP ALG

    Disable SIP ALG and save the settings to prevent it from affecting communication between 3CX and Internetport.

Configure NAT and Static IP in 3CX Admin

To ensure correct NAT traversal, you need to configure your 3CX server with a static IP address:

  1. Step 1: Log In to 3CX Admin Page

    Go to https://[your-server-ip]:5090 and log in with your credentials.

  2. Step 2: Configure Static IP Address

    Navigate to network configuration settings and enter the static IP address that your router has allocated for the 3CX server.

  3. Step 3: Enable NAT Traversal

    Find the NAT traversal setting and enable it to ensure correct communication through NAT.

Test with 3CX Firewall Checker

To verify that all ports are correctly configured, you can use 3CX's built-in firewall test tool:

  1. Step 1: Open Firewall Checker

    Go to https://[your-server-ip]:5090, log in, and navigate to the firewall test tool.

  2. Step 2: Run the Test

    Click the button to start the test and wait for it to complete. The test will check if all necessary ports are open.

  3. Step 3: Review Results

    Check the results to see if there are any issues with port configuration. Resolve any problems according to the recommendations in the test results.

Common Issues

  • Features Work on LAN but Not Outside: Check that all necessary ports are open both incoming and outgoing. Ensure that SIP ALG is disabled in the router.
  • Communication Problems with RTP Streams: Verify that UDP port range 10000-20000 is open both incoming and outgoing. Also check that NAT traversal is enabled in 3CX.
  • Tunnel Communication Fails: Ensure that TCP port 443 is open for outgoing traffic. Check also that there are no firewalls or security programs blocking communication on this port.

For further assistance and support, visit Internetport's support page.