3cx- PfSense firewall check errors

Status
Not open for further replies.

roshansimon

Free User
Joined
Jan 19, 2020
Messages
58
Reaction score
3
Hi..

This is a new install. The 3cx software is behind the PfSense (Router/firewall) on the LAN on a seperate VLAN, for Voice.
When running the Firewall checker I'm getting a bunch of errors. I have a doubt whether the ISP (TELUS) has an issue with the Port 1 for bridge, because I cant even ping the WAN IP. But TELUS tech support is utter crap. I just want to be sure if it is an issue with the bridge or my NAT rules.

(I was referring the document: https://www.3cx.com/docs/pfsense-firewall/ )

Attachment1: Firewall checker Results.
Attachment2: Pfsense NAT Port Forwarding
Attachment3: PFsense Port Preservation

Please assist.
Thanks in advance.
 

Attachments

  • Pfsense NAT Port forwarding.JPG
    Pfsense NAT Port forwarding.JPG
    65.3 KB · Views: 37
  • Pfsense NAT Port preservation.JPG
    Pfsense NAT Port preservation.JPG
    64.3 KB · Views: 37
  • 3cx-firewall-checker error-min-min.jpg
    3cx-firewall-checker error-min-min.jpg
    1.8 MB · Views: 37
Just to add, there are no other firewall rules setup now, and the Pfsense box is wide open. I want to get this working, before I tie down on the rules.
 
If you follow that guide you should be good on the firewall side of things
 
The document @cobaltit sent, it looks like you have not completed step 2 as there is no rule in your seconds screen shot to preserve ports
 
You are @diamond9... I forgot to move my preserve port to the top of the list. Screenshot attached. Moved it to the top, but I still get the same errors. [Screenshot attached for preserve ports.]
 

Attachments

  • 3.JPG
    3.JPG
    88.2 KB · Views: 20
TELUS tells me that they need to do MAC address reservations for getting a STATIC IP.. If TELUS reserves the MAC address for the 3CX box; and the 3cx box is behind the PFsense box, will NAT work?
I tried a PING test (after enabling ICMP on Pfsense) and that did not work.
 
I connected 3cx box directly to the Telus router, and my public IP is pingable. But not behind Pfsense box.

Would NAT 1:1 on Pfsense help?
 
Would NAT 1:1 on Pfsense help?

This is pretty much the expectation from 3CX 1>1 NAT/Full cone NAT setup for public to private IP by 3CX for on premise servers: https://www.3cx.com/blog/voip-howto/static-port-mappings/

We setup software Pfsense all the time (albeit on the edge of a hosted system for VPN or SBC connection) I can send some configuration notes if desired however it sounds like you are doing on-premise here (which we 99% of the time never do).
 
Thanks @eddv123
But how do I configure multiple NAT on the pfsense?
One for the Pfsense box that is connected to the ISP bridged modem/router , and the other is the non-DMZ 3cx server.
I just want to find the best method to implement proper multiple NAT to external IPs, on the pfsense.
 
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,816
Latest member
natedog