To ensure that your 3CX server works correctly with Internetport, you need to open specific ports in both the firewall and the router. This guide provides a detailed port list for SIP, RTP, tunnel, and web admin, as well as instructions on how to configure NAT and disable SIP ALG.
Port Overview: SIP, RTP, Tunnel, Web Admin
For 3CX to communicate with Internetport, several ports need to be open. Here is an overview of the most important ones:
- SIP (Session Initiation Protocol): Port 5060 UDP/TCP
- RTP (Real-time Transport Protocol): Port range 10000-20000 UDP
- Tunnel: Port 443 TCP for secure communication
- Web Admin: Port 5090 TCP for access to the 3CX admin page
Incoming Rules That Must Be Open (Port List)
To receive calls and data from Internetport, you need to configure the following incoming ports in your router:
Step 1: Open SIP Port
Open UDP/TCP port 5060 to allow SIP communication. This is the primary communication port for calls and messages.
Step 2: Open RTP Port Range
Configure UDP port range 10000-20000 for RTP streams. This port list is used to transfer voice data in real-time.
Step 3: Open Tunnel Port
For secure communication, open TCP port 443, which is used for tunnel communication to Internetport's SIP server.
Step 4: Open Web Admin Port
TCP port 5090 should be open to provide access to the 3CX admin page, which is useful for management and configuration.
Outgoing Rules to Internetport SIP Server
To ensure outgoing communication to Internetport's SIP server, you need to configure the following outgoing ports:
Step 1: Configure UDP/TCP Port 5060
Allow outgoing traffic on UDP/TCP port 5060 to initiate SIP sessions to Internetport's SIP server.
Step 2: Configure RTP Port Range
Allow outgoing UDP traffic in the port range 10000-20000 to send voice data to Internetport's SIP server.
Step 3: Configure Tunnel Port
Allow outgoing TCP traffic on port 443 for secure communication with Internetport's SIP server via a tunnel.
SIP ALG - Why It Causes Problems and How to Disable It
SIP Application Layer Gateway (ALG) can disrupt 3CX communication by manipulating SIP messages. Therefore, it is recommended to disable SIP ALG in your router:
Step 1: Log In to Router Admin
Go to your router's admin interface by entering the IP address in a web browser.
Step 2: Find SIP ALG Settings
Locate the SIP ALG settings, which are often found under advanced network settings or QoS (Quality of Service).
Step 3: Disable SIP ALG
Disable SIP ALG and save the settings to prevent it from affecting communication between 3CX and Internetport.
Configure NAT and Static IP in 3CX Admin
To ensure correct NAT traversal, you need to configure your 3CX server with a static IP address:
Step 1: Log In to 3CX Admin Page
Go to
https://[your-server-ip]:5090and log in with your credentials.Step 2: Configure Static IP Address
Navigate to network configuration settings and enter the static IP address that your router has allocated for the 3CX server.
Step 3: Enable NAT Traversal
Find the NAT traversal setting and enable it to ensure correct communication through NAT.
Test with 3CX Firewall Checker
To verify that all ports are correctly configured, you can use 3CX's built-in firewall test tool:
Step 1: Open Firewall Checker
Go to
https://[your-server-ip]:5090, log in, and navigate to the firewall test tool.Step 2: Run the Test
Click the button to start the test and wait for it to complete. The test will check if all necessary ports are open.
Step 3: Review Results
Check the results to see if there are any issues with port configuration. Resolve any problems according to the recommendations in the test results.
Common Issues
- Features Work on LAN but Not Outside: Check that all necessary ports are open both incoming and outgoing. Ensure that SIP ALG is disabled in the router.
- Communication Problems with RTP Streams: Verify that UDP port range 10000-20000 is open both incoming and outgoing. Also check that NAT traversal is enabled in 3CX.
- Tunnel Communication Fails: Ensure that TCP port 443 is open for outgoing traffic. Check also that there are no firewalls or security programs blocking communication on this port.
For further assistance and support, visit Internetport's support page.