Annoyed by Firewall Test Fails

Status
Not open for further replies.

ajohnson443

New User
Joined
Mar 27, 2012
Messages
48
Reaction score
9
My system has been working fine for a while, never have any issues with dropped calls or audio etc.. But the RED Exclamation for the firewall test is annoying me to death lol! ALL the ports are open but some ports always fail (randomly) during the test.. Any idea how to resolve? Or should I just get over it? lol :D

Router:
Nighthawk(R) X4S R7800
Firmware Version V1.0.2.68
1584705634719.png

Firewall test results (removed the passing ports for brevity)
  • resolving 'stun.3cx.com'... done
  • resolving 'stun.callwithus.com'... done
  • resolving 'stun.sipgate.net'... done
  • resolving 'sip-alg-detector.3cx.com'... done
  • testing 3CX SIP Server... done
    • stopping service... done
    • detecting SIP ALG... not detected
    • testing port 5060... done
    • starting service... done
  • testing 3CX Tunneling Proxy... done
    • stopping service... done
    • testing port 5090... done
    • starting service... done
  • testing 3CX Media Server... failed (How to resolve?)
 
Hi @ajohnson443

Does your firewall documentation contain information about how to open ports as full cone NAT?

Also the complete range of our media server 9000-10999 but the screenshot of your rules does not seem to cover all ports https://www.3cx.com/docs/ports/
 
  • Like
Reactions: ajohnson443
Although completely obvious, surely just replicate what you have done for 5060 and 5090 (since they look to have passed - although I cannot see the colours) for the media port range.
 
  • Like
Reactions: ajohnson443
Hi @ajohnson443

Does your firewall documentation contain information about how to open ports as full cone NAT?

Also the complete range of our media server 9000-10999 but the screenshot of your rules does not seem to cover all ports https://www.3cx.com/docs/ports/

I only included the failed ports in the report. Everything else passes. The failed ports are random, not always the same ones..

All the required ranges are open/forwarded in the firewall settings.

I wonder if it is a time-out issue the part of the tester?

I can't post the full test due to too many characters so I attached a text file. Notice this time 5060 failed too.. See what mean about random? The system works fine.. this is just annoying.
I am OCD about that darn little 1584832447736.png on my dashboard :)
 

Attachments

I've had the same issue at some site. I just ignore it and everything works fine. Honestly, it just matches my non supported SIP trunk ! and my non supported phones !
 
  • Haha
Reactions: ajohnson443
Hi @ajohnson443

Does your firewall documentation contain information about how to open ports as full cone NAT?

Also the complete range of our media server 9000-10999 but the screenshot of your rules does not seem to cover all ports https://www.3cx.com/docs/ports/

I just re-did all the port forwarding using the chart you linked to.. Consolidated TCP, TCP/UDP, & UDP into single entries to make it easier to look at :P

1584834480988.png
 
But did the firewall checker pass?
 
Can't say about the specific firewall as we do not provide support on those, but depending on the model/vendor and depending on how strict your rules are (with regards to the PBX being allowed to contact the 3CX firewall checker server IPs) you might have inconsistent results.

I believe if it supported full NAT you would not have the intermittent/random failures. You can of course hook up the PBX straight into your modem/CPE with DMZ mode enabled for the PBX machine's private IP and see if the issues go away (to pinpoint the router as a possible cause)
 
  • Like
Reactions: ajohnson443
I already have a DMZ server for something else and I'm not going to upset the apple cart just to satisfy my OCD :)

Ran a test with an analyzer online.. NAT all seems to be setup correctly.

Here are the results of the test:

UPnP Test (?):No UPnP device found

STUN Test (?):Full Cone NAT

UDP Binding Test (?):Endpoint independent binding, port prediction is easy
TCP Binding Test:Endpoint independent binding, port prediction is easy

UDP Mapping Test (?):your external IP address was different from your local one (NAT).
Your external source ports were preserved on every connection.
TCP Mapping Test:your external IP address was different from your local one (NAT)
Your external source ports were preserved on every connection.

SIP ALG (?):The initial SIP INVITE packet has not been modified on its way to our servers.
There is no SIP ALG involved
FTP ALG:The initial FTP PORT command has been modified.
Most probably, your NAT implements a FTP-ALG

UDP Hole Punching (?):High TTL Test was not successful
Low TTL Test was successful
Silent Test was not successful
TCP Hole Punching:High TTL Test was not successful
Low TTL Test was not successful
Silent Test was not successful

UDP Timeout (?):Your UDP timeout is approx. 32 seconds
There should be no problem when refreshing bindings.m
 
You're still failing the full cone tests, that 3rd party test does not check the specific things 3CX does.

You can continue to use your system by all means, but I would expect that at some point external calls may show issues or they may have problematic audio and you will have to come back to this.
 
Status
Not open for further replies.

Forum statistics

Threads
111,940
Messages
589,850
Members
164,830
Latest member
business@brightwaylogisti