Solved 3CX on OVH Firewall Test fails ports over 9500

Status
Not open for further replies.

Chrischevy80

Free User
Advanced Certified
Joined
Oct 1, 2017
Messages
37
Reaction score
4
On 3 brand new installations on OVH (PBX Express), the firewall test fails after port 9500.

There is another thread (locked) on the subject: https://www.3cx.com/community/threads/rtp-ports.57330/

I do not know of any firewall configuration at OVH. Anyone has a clue ?
 
Did you check if the iptable is set-up correctly?
 
Did you check if the iptable is set-up correctly?
No because I tought that 3CX would take care of this. I know it's an ip tables issue but these are brand new installs with PBX Express, shouldn't it work out of the box ?
 
Thanks I saw that but 3CX support user YiannisH_3CX said "Did you download the latest 3CX iso to install the PBX? If so the IP tables should have been already pre-configured to accommodate the new ports." So i guess that 3CX should be able to fix this with a patch or something.

I'll go the iptables way if I absolutely have to, but I would prefer if 3CX fixed it themselves.
 
Please note that if the account has pre-configured firewall rules, the PBX express wizard will not make any adjustments to those. So if you have 3 new instances under an account that already has firewall rules the PBX express wizard will not make any changes as these rules could have been configured by the account admin. If this is the case you will need to manually adjust the rules to accommodate for the new ports.
 
Please note that if the account has pre-configured firewall rules, the PBX express wizard will not make any adjustments to those. So if you have 3 new instances under an account that already has firewall rules the PBX express wizard will not make any changes as these rules could have been configured by the account admin. If this is the case you will need to manually adjust the rules to accommodate for the new ports.

Thanks for your reply. What "account" are you referring to ? These systems are all independant from one another (no common "account") Unless you are talking about the OVH account.
 
Do you have other VW's running on any of the OVH Accounts?
 
Yes i am referring to the OVH account
 
In my OVH account, I followed the instructions here: https://www.3cx.com/docs/cloud-pbx-ovh/
I now have 3 installations running in my Public Cloud Projet, all with different Openstack users. I don't see anything related to preconfired firewall rules and I am the admin and it's a brand new account. To me, the fact that only ports higher than 9500 are blocked indicates that 3CX doesn't configure the firewall properly during the original setup. If I'm not mistaken, I think that in older versions of 3CX, the RTP ports stopped at 9500 (I couldn't find the old admin manual to confirm this)
 
In my OVH account, I followed the instructions here: https://www.3cx.com/docs/cloud-pbx-ovh/
I now have 3 installations running in my Public Cloud Projet, all with different Openstack users. I don't see anything related to preconfired firewall rules and I am the admin and it's a brand new account. To me, the fact that only ports higher than 9500 are blocked indicates that 3CX doesn't configure the firewall properly during the original setup. If I'm not mistaken, I think that in older versions of 3CX, the RTP ports stopped at 9500 (I couldn't find the old admin manual to confirm this)
I would recommend creating a ticket regarding this issue with our support department so they can look into the issue and determine what might be causing this.
 
In my OVH account, I followed the instructions here: https://www.3cx.com/docs/cloud-pbx-ovh/
I now have 3 installations running in my Public Cloud Projet, all with different Openstack users. I don't see anything related to preconfired firewall rules and I am the admin and it's a brand new account. To me, the fact that only ports higher than 9500 are blocked indicates that 3CX doesn't configure the firewall properly during the original setup. If I'm not mistaken, I think that in older versions of 3CX, the RTP ports stopped at 9500 (I couldn't find the old admin manual to confirm this)
Launch openstack in OVH, navigate to Network, Security Groups, PBX Express, Manage Rules and add new rules 9000-10999 and delete the old rules. Run firewall checker again on 3cx.
 
Launch openstack in OVH, navigate to Network, Security Groups, PBX Express, Manage Rules and add new rules 9000-10999 and delete the old rules. Run firewall checker again on 3cx.

Wow thanks, I didn't know about this configuration ! Funny thing is, all rules are ok. I just re-ran the firewall check on all my 3CX servers and everything is fine now. Someone must have fixed something because I didn't touch anything !
 
Glad to see the issue has been resolved and thank you for updating the thread.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,891
Messages
589,590
Members
164,757
Latest member
shakk