Connection to Webclient refused

jkbavaria

Customer
Mitglied seit
1. Mai 2021
Beiträge
26
Hello!

I have some Windows 10 - PCs im my LAN.
When I connect to https://fqdn.my3cx.de:5001/webclient all ist working fine.
But on one PC I'm getting CONNECTION REFUSED (using differend browsers).

Why?
 
Hello,

PC IP in 3CX blacklistet? Split DNS in LAN properly configured?
 
Hello.

I don't think it's that. For the test, I deleted the complete blacklist (-> export). Unfortunately, that didn't work.
The client has the same WAN IP as the other clients in the network.
So I don't think it's related to the blacklist.
 
Client and WAN IP? Why?

Connect via LAN IP (not FQDN) and with cert error is functional?
 
Yes!
I can access normally via the LAN-IP!
The certificate warning comes, but you can skip it.
To use the chrome add-ons I have to use the FQDN, otherwise the add-on sometimes won't start (because of the certificate warning).
That's why I want to dial in through the FQDN.
I've also used my WAN IP before:
Unfortunately I got the same error message.
 
Then it's a DNS problem, on your client or your local DNS Server. If you ask nslookup <3cx-fqdn> on the client you should get a proper answer: the right 3CX LAN IP.

Dont's use your WAN IP, use LAN IP for tests. You should always use your 3CX FQDN which should resolve to the 3CX LAN IP.
 
nslookup fqdn.my3cx.de
Server: server.my.lan
Address: 192.168.1.1 (IP of my local DNS-server)

Nicht autorisierende Antwort:
Name: fqdn.my3cx.de
Address: x.x.x.x

x.x.x.x is the correct WAN IP of my network


Everything looks correct.
 
Wenn du schon ein deutsches Forum besuchst und deutsche Antworten von deinem nslookup bekommst dann können wir auch in deutsch weiter schreiben.

Aber: da sollte als Antwort nicht die WAN IP deines Netzwerkes stehen sondern die LAN IP der 3CX (sofern sich Client und 3CX hinter der gleichen öff. IP / Router befinden). Das nennt sich Split DNS.
 
Was für ein Gerät ist denn dein lokaler DNS Server, der mit der IP 192.168.1.1?
 
Hallo.

Ja, deutsch ist einfacher... ;-)

Der FQDN entspricht erstmal ja nir der WAN-IP des Routers. Erst der Port 5001 zeigt an, welches Gerät im LAN gemeint ist. Deshalb kann eigentlich nur die WAN-IP des Routers heraus kommen.
 
Was mich wundert: Bei allen anderen Windows-PCs funktioniert alles perfekt.
 
Richte in dem DNS Server im Ubuntu einen Verweis auf den FQDN der 3CX ein, abhängig vom DNS Server in etwa so:
fqdn.my3cx.de IN A <LAN IP der 3CX>
Evtl. noch eine TTL angeben. An der 3CX auch mal IPv6 deaktivieren (unter Einstellungen / Netzwerk die IPv6 Bindung deaktivieren). Dann ipconfig /flushdns am Client, dann das Ganze mit nslookup fqdn.my3cx.de testen und da muss die korrekte IPv4 LAN IP der 3CX kommen.
 
  • Like
Reaktionen: fxbastler
Hello.

I don't think it's that. For the test, I deleted the complete blacklist (-> export). Unfortunately, that didn't work.
The client has the same WAN IP as the other clients in the network.
So I don't think it's related to the blacklist.
Export ist aber nicht zum löschen da?!
Erstell sonst sicherheitshalber mal einen Allow-Eintrag für das lokale Subnetz (nur zum testen).
 
Nein. Aber wenn die Liste leer ist ...
 

Zurzeit aktive Besucher

Statistik des Forums

Themen
44.314
Beiträge
232.388
Mitglieder
78.275
Neuestes Mitglied
Norbert Schütze