Solved 3CX Full cone test failed on firewall check.

Status
Not open for further replies.

thomashill3525

New User
Joined
Jun 30, 2024
Messages
7
Reaction score
1
I've been looking at other posts on this forum to people with the same issue, however none of their solutions worked for me.
1719762248277.png
Just to briefly explain my network, I have a DSL line coming in from BT, which goes into EE's provided router, I'm stuck using this router at the moment due to our analog phones currently relying on EE / BT's digital voice service.
My actual network is behind a pfSense firewall, which links out of one of the lan ports of the BT into the pfSense's WAN port. Unfortunately my ISP provided router doesn't have any form of bridge mode, however I am able to place my firewall into the DMZ, which has worked for other use cases, I can run game servers out to the internet just fine, and use services like openVPN to tunnel into my home network whenever I am away from home and need to access my NAS or PC.

My EE Router is on the 192.168.3.xxx range, as 192.168.3.254, and on the WAN side my pfSense router has a static IP of 192.168.3.250. On the LAN side my pfSense router is 192.168.0.1 and my 3CX VM is 192.168.0.11

In terms of setting up 3CX, I'm using a Proxmox VM for the first time, as it would be great to be able to deploy one machine with many VM's running on it, but for the moment there is just one 3CX instance on it. When looking on how to setup my firewall with 3CX, I came across this guide which I have followed, but I'm still running into cone test failures: https://www.3cx.com/docs/pfsense-firewall/
Below are some screenshots of my NAT & Firewall rules, and other relevant settings.
1719762616614.png

1719762456303.png
1719762474048.png
1719762754338.png

HTTP & HTTPS Ports were allowed through just to see if I could log onto 3CX from the internet, which I can, which seems odd. If I can access the 3CX webpage both from my IP and domain provided by C3X, as well as OpenVPN, why am I getting all of these errors with the firewall check?
 

Attachments

  • 1719762445123.png
    1719762445123.png
    44.5 KB · Views: 12
Use Wireshark and filter UDP to see the outcome based on the guide that was provided above by @SteveITS
for example, if its a port 5060, use, filter: udp.port==5060
 
So after doing some packet capturing with pfSense and examining them in wireshark I could see the same issue replicated on Test 2 of 3cx's firewall checker dock. After looking at other full cone situations with pfSense I have managed to get full cone on my PC by disabling the windows firewall. However I'm still running into issues on my 3cx instance on proxmox, so I'll be having a look there, I might just need to add in a static nat mapping for the proxmox server (with the already existing static mapping for the 3cx instance)
1719787408724.png

Edit: might try installing a windows (maybe server) VM and run 3cx on that, and see if I get anywhere, but I've confirmed I can get full cone NAT on both inside my ISP router, and my double natted pfSense machine
 
Last edited:
So, I've eliminated proxmox as a whole just to narrow the possible issues down, I've installed 3cx on a windows dedicated machine, and have added its IP address into all of the relevant configurations in pfSense, and the nat type tester tool does detect it to be a full cone nat, yet im still running into issues with 3cx. (Both 3cx and nat type tester are running on the same machine)

1719789672145.png

However following 3cx's documentation, it shows that the server sent the requests 3 times without getting a reply from the stun server. 1719790119188.png
(192.168.3.250 being my pfSense firewall on the WAN side)
 
Last edited:
3 Replies in a row from myself, just been trying several things and I have come to this rough conclusion. So I've done some more packet capturing but all UDP requests, and just narrowed them down to the classic-stun protocol, and the only external IP which enters my WAN is 192.248.177.74, which shows that the other servers attempting to get through simply cant. The packet capture has been done on the wan side of my pfsense which is linked to my EE Routers LAN, and I have a feeling that the EE router is blocking or dropping the incoming UDP, even though pfSense is in the DMZ. So either I've missed a setting somewhere in my pfSense on the WAN interface / or firewall rule. Or EE in all of their wisdom is just dropping my incoming UDP

1719791469159.png
 
New discovery haha, so I ended up adding the portforwarding rules into my EE router as well as pfSense, and behold I start getting succesfull port checks, however port 5060 is still failing for some reason, and I cant figure out why.
1719792246618.png
1719791746392.png
 
Are you using any telephon stuff on the ISP router? Than its that why your portcheck failed.
 
If the port is used from your router this can cause the issue.
 
  • Like
Reactions: bitn2
I gathered that was the case, in the UK most of our analog phone services are being switched off and replaced with "Digital Voice" which travels down the same DSL line or FTTP. Whilst EE keep details their Digital Voice hidden, it is most likely some form of VOIP which utilizes port 5060.

I've got a draytek router which I can put into a bridge mode to act as a modem, so I can use that to get my broadband from the DSL without using EE's router, if all goes to plan then I'll just purchase some FXS adapters so I can use my voip number on my existing DECT handsets, and ditch the crappy EE provided router for good, and be rid of my double nat situation, and my pfSense machine will be the only router/firewall.

Atleast then if we were to switch from EE later on, we wouldn't be bound to requiring a phone service, or have to change the number, since we are reliant on there being some form of phone line to take calls for gated entry.
 
Last edited:
Let us know the outcome ;)
 
Is your ISP BT or EE? Note that EE's internet will be CGNAT if youre using their data broadband.
 
My ISP is EE, but most there services depend on BT. So what I've done is used my draytek vigor router as a modem and I have directly passed the PPPOE to my pfsense machine, which is now receiving my public ip on the WAN and like magic, its all working. So the lesson here is dont use shitty ISP provided routers.
1719827221199.png
1719827259795.png
 
  • Like
Reactions: OlegR_3CX
Glad to know this is now resolved ;)
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,973
Messages
590,074
Members
164,895
Latest member
jasonkkrause