Author Topic: What Firewall Ports do you need open between UCA Softphone and a 5000  (Read 18072 times)

Offline akuhn

  • Sr. Member
  • ****
  • Posts: 339
  • Karma: +1/-0
    • View Profile
Cross Posted with the Applications Forum

PBX - 5400
MAS/UCA Server
NO MBG
NO Teleworker

UCA Client External.

Those who have followed my posts know I scored a major victory by getting the UCA Softphone to work outside of my office yesterday.  That's the good part.

The part I want to refine is closing unnecessary ports on my external facing firewall between the Internet and the two publicly facing IP addresses on my 5400 and expansion chassis. 

In order for the softphone to work, I have to open ALL ports to my PBX and expansion chassis. 

On Page 13 of the Engineering Guide for the UCA with no MBG, it states that the following ports need to be open:

3998-3999    TCP

5060        UDP

6004-6261    UDP
6604-7039    UDP
5004-5070    UDP

6800-6802    UDP

50098-50508    UDP

5566    TCP

5567    UDP

5570    TCP

4000    TCP

4000    TCP

44000    TCP

69    TCP

20001    TCP

I've opened these ports up and more, but the softphone doesn't work unless I open up all the ports.  So I have to assume this list is incomplete or not providing necessary details.

Anyone have a list of ports for a softphone and a 5000 Series?


Offline marcolive

  • Full Member
  • ***
  • Posts: 131
  • Karma: +2/-0
    • View Profile
Re: What Firewall Ports do you need open between UCA Softphone and a 5000
« Reply #1 on: February 29, 2012, 09:08:59 PM »
Hi,

I've never had to do that with a UCA softphone. Do you have any king of call control and just no audio, or nothing at all?

Try to open ports 6800-6802 TCP.  These ports are for Minet (call control).  I think the best way to troubleshoot that kind of problem is to do a Wireshark capture and analyze requests from UCA client to the 5000. 

Keep us in touch!

Offline akuhn

  • Sr. Member
  • ****
  • Posts: 339
  • Karma: +1/-0
    • View Profile
Re: What Firewall Ports do you need open between UCA Softphone and a 5000
« Reply #2 on: February 29, 2012, 09:30:45 PM »
I will add your TCP suggestions to the mix.  As to your first question, you get a Red X and no ability to call.  If I open up all ports, then the X goes away and calling proceeds. 

Offline NTEDave

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 502
  • Country: gb
  • Karma: +11/-0
    • View Profile
Re: What Firewall Ports do you need open between UCA Softphone and a 5000
« Reply #3 on: March 01, 2012, 02:43:44 PM »
In my notes I have an open port range of 6004 to 7039 UDP, you have a 'hole' of closed ports in the range from 6261 to 6604 UDP.

Worth a shot??

Offline akuhn

  • Sr. Member
  • ****
  • Posts: 339
  • Karma: +1/-0
    • View Profile
Re: What Firewall Ports do you need open between UCA Softphone and a 5000
« Reply #4 on: March 01, 2012, 02:45:59 PM »
I lost my remote access to my home computer (via Windows Home Server) because I think I left the connection up too long and it timed out.  So I will test these out as soon as possible.  I'd rather have 500 ports open than 55K ports open.

Offline akuhn

  • Sr. Member
  • ****
  • Posts: 339
  • Karma: +1/-0
    • View Profile
Re: What Firewall Ports do you need open between UCA Softphone and a 5000
« Reply #5 on: March 02, 2012, 02:53:26 PM »
BINGO!

I threw both 6800-6802 TCP and 6004 to 7039 UDP into my "Mitel PBX Ports" service group object in my Sonicwall.  My softphone still works.

I also took out the Webserver ports (http and https) because I didn't think they were necessary.

If you doing this, you should be aware that you might still see the Red X on the drop down menu of your UCA Client when you switch from the deskphone to the softphone.  Don't let that stop you from actually selecting the softphone.  Only when you've selected the softphone and seen whether you have the X or not is the final test. 

Thanks for the suggestion.




 

Sitemap 1 2 3 4 5 6 7 8 9 10