3cx behind Sophos UTM via WAF/Reverse Proxy possible?

Status
Not open for further replies.

Apoo

Silver Partner
Joined
Apr 13, 2018
Messages
4
Reaction score
0
Hello all,

about 1.5 years ago I had tested if the 3cx is possible behind a Sophos UTM with WAF/Reverse Proxy, which had not worked.
After entering the login data on the web client website, just nothing went on.

The normal procedure to change port from 5001 to 443 with backup, reinstall and import was executed.
When port 443 is NATed, it works, as soon as the Web Protection (what Sophos calls the Reverse Proxy) is switched on, the above mentioned error comes up, even if the WAF is configured to completely let everything through without any further rule.

WAF/Reverse Proxy is necessary because the customers usually have only one public IP but also Exchange servers on site. Access for OWA but also Active Sync/Outlook Anywhere works without problems. But 3cx resists.

Does anyone know this problem? We have about 10x 3cx instances at our customers and we always get the requests that the system must be accessible without port directly via 443 instead of 5001, because externals often only have 80 and 443 outgoing accessible.

VG Johnny
 
Hello all,

about 1.5 years ago I had tested if the 3cx is possible behind a Sophos UTM with WAF/Reverse Proxy, which had not worked.
After entering the login data on the web client website, just nothing went on.

The normal procedure to change port from 5001 to 443 with backup, reinstall and import was executed.
When port 443 is NATed, it works, as soon as the Web Protection (what Sophos calls the Reverse Proxy) is switched on, the above mentioned error comes up, even if the WAF is configured to completely let everything through without any further rule.

WAF/Reverse Proxy is necessary because the customers usually have only one public IP but also Exchange servers on site. Access for OWA but also Active Sync/Outlook Anywhere works without problems. But 3cx resists.

Does anyone know this problem? We have about 10x 3cx instances at our customers and we always get the requests that the system must be accessible without port directly via 443 instead of 5001, because externals often only have 80 and 443 outgoing accessible.

VG Johnny
Hello,
I have been using Sophos UTM v9 and 3CX for 2-3 years now without any problems (at least for the one instance of 3CX i am using). I am using TCP 3003 for web interface.
Web interface (user / admin) works great. But some WAF rules have to be deactivated, or login might Not work (that was the case too with Synology NAS behind Sophos).
3CX tunnel for communication (or SIPS / SRTP) is natted.

Web protection is not linked to Reverse Proxy / WAF. You might be confusing with Webserver Protection ?

I have a YT Channel for security with Sophos and NAS, unfortunately i did not with 3CX because i thought no one would be interested in this architecture with 3CX / Sophos aha.
 
Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet