SIP-TRUNKING TECHNICAL 3CX

3CX SIP Trunk Setup: V20 Custom Trunk Guide

SIPNEX ·

Adding a custom SIP trunk to 3CX V20 takes four steps — Admin › Voice & Chat › Add Trunk, pick the Generic template, enter your carrier’s registrar and credentials, then add your DIDs. One licensing note: under 3CX’s pre-2026 lineup, generic (non-”supported provider”) trunks required a paid PRO or ENTERPRISE license; since 3CX’s 2026 Basic/Free restructuring, its comparison table lists SIP Trunk Choice on all editions — check your key’s current terms. Either way, 3CX states plainly that it does not assist with unsupported-provider configuration.

This guide is written by SIPNEX, an FCC-licensed carrier, for operators pointing 3CX at a carrier of their own choosing. The settings below are the generic values any SIP carrier uses, with SIPNEX’s specifics supplied during provisioning. If V20 licensing is what brought you here, the 3CX alternatives after the licensing changes guide maps the exits.

Before you start: the license question

Know which 3CX you are running:

  • Self-managed V20 on a current (2026) key: since 3CX’s 2026 restructuring — the lineup is now Free/Basic/PRO/AI — 3CX’s comparison table lists SIP Trunk Choice on all editions, and its current SIP trunk documentation shows no license gate. This guide applies directly; still verify your own key’s terms, since 3CX licensing has changed repeatedly.
  • Older pre-2026 keys (V20 SMB-era lineup): generic trunks were gated behind PRO or ENTERPRISE, and on the legacy free/SMB tier the Generic option was not selectable. (The old SMB FREE edition has been wound down: closed to new users around the start of 2026, existing keys extended to December 31, 2026, then losing Portal access in March 2026 with a stated downgrade to Basic.)
  • Hosted by 3CX: operators have reported the Generic option missing on 3CX-hosted V20 instances even where V18 had it — if your instance is 3CX-hosted, confirm the option exists before committing to a carrier migration.

What you need from the carrier is the standard list: SIP registrar/proxy address, authentication method (registration credentials or IP-based), your DIDs, and the codec/DTMF expectations. SIPNEX provisions all of it — registration or IP auth, G.711u primary, RFC 2833 DTMF — within one business day.

Adding the trunk in the Admin Console

  1. Admin › Voice & Chat › + Add Trunk. Give the trunk a name and a default route (where unmatched inbound calls land).
  2. Under SIP Trunk Details, set the country and choose the Generic entry in the Trunk drop-down.
  3. Enter the registrar (your carrier’s SIP server) and the Main Trunk No — 3CX requires a main number for the trunk.
  4. Choose the authentication mode. Register-based: enter the Authentication ID and password from your carrier. IP-based: no registration — but the carrier must whitelist your PBX’s public IP, and if you ever move or rehost the instance you must tell the carrier the new IP before calls will flow.
  5. DID Numbers tab › + Add (or CSV import) for every number the carrier routes to you. Then assign DIDs to users or system extensions under their Call Handling settings — any DID you leave unassigned follows the trunk’s default route.
  6. Create an outbound rule (Call Routing) so outbound traffic selects this trunk by prefix, extension group, or number length.

Codecs and DTMF

Set codec order per trunk under the trunk’s Options tab › Codec Priority. For most North American deployments the right order is G.711u first — it is the PSTN-native codec and the quality baseline. Note two 3CX behaviors: on inbound calls the provider’s codec ordering wins regardless of your priority list, and 3CX anchors/transcodes trunk media, so carrier-to-endpoint RTP always flows through the PBX.

DTMF needs no configuration: 3CX offers RFC 2833 telephone-event in every SDP and falls back to in-band when the far side offers none — which is exactly what carriers like SIPNEX expect.

Firewall and NAT

3CX is opinionated here, and fighting it costs weekends:

  • Run the built-in Firewall Checker before going live.
  • Forward SIP 5060 (UDP/TCP) and the RTP range 9000–10999 UDP — that RTP range is fixed in 3CX and cannot be changed; budget two ports per call.
  • Disable SIP ALG on your router — the single most common cause of one-way audio and dropped registrations. Our SIP troubleshooting posts cover why.
  • Set your public IP under Advanced › Network › External IP configuration. 3CX does not recommend or support STUN for trunk deployments — a static public IP is the expected setup.

Testing the trunk

Register (or place the first IP-auth call), then verify in both directions: an outbound call to a cell phone (check the caller ID you configured), and an inbound call to each DID pattern (check it lands on the intended extension, queue, or IVR). If outbound connects but inbound dies at the trunk, the culprit is usually an unassigned DID or the default route pointing nowhere.

Frequently asked questions

Can I use a custom SIP trunk on free 3CX?

It depends on your key’s vintage. Under the pre-2026 lineup, the free/SMB tier limited trunk creation to 3CX’s supported-provider list and the Generic template required a PRO or ENTERPRISE license. Since the 2026 Basic/Free restructuring, 3CX lists SIP Trunk Choice on all editions — including the self-hosted 4SC Basic Free edition — though it does not assist with unsupported providers. 3CX-hosted instances have reportedly lost the Generic option in V20, so verify before migrating.

Does 3CX support IP authentication for trunks?

Yes — generic trunks can run register-based (Authentication ID + password) or IP-based, where the carrier whitelists your PBX’s public IP instead. IP auth suits static-IP deployments; remember that rehosting the PBX means updating the whitelist with your carrier before calls flow again.

What codecs does 3CX V20 support on trunks?

G.711 a-law and u-law, G.722, G.729a, GSM-FR, iLBC, Speex, and Opus, ordered per trunk under Options › Codec Priority. For US carrier trunks, G.711u first is the standard choice. Inbound calls follow the carrier’s codec ordering rather than the trunk’s priority list.

Why does my 3CX trunk register but calls have no audio?

Almost always NAT: the RTP range 9000–10999 UDP isn’t forwarded to the PBX, the router’s SIP ALG is mangling packets, or the external IP isn’t set under Advanced › Network. Fix those three and one-way/no audio issues disappear in the vast majority of cases.


SIPNEX provisions dialer-grade SIP trunks for any PBX — registration or IP auth, unlimited channels, A-level STIR/SHAKEN attestation signed with our own certificate, and engineers who can read your 3CX Activity Log with you. Connect your PBX or see rates.

SIPNEX

The carrier built by operators, for operators.

FCC-licensed carrier with its own STIR/SHAKEN SP certificate. Operator-owned. SIP trunks built for operators who dial at volume.