Another issue with Firewall Check.

Status
Not open for further replies.
Hi,
@BrenttG If you read the post before, I removed everything from the provider!
I have directly PPPOE tunneling coming to pfsense. pfsense has the fixed ip assigned.
I will check for the MTU... but If the MTU was not correct I think I will have other issue! And maybe bigger issue!

"some of the ports are not NATing" for example 5060 can be accessed for ouside my network via the fixed IP and I can view the access via wireshark on the server (windows 2019 server) executing 3CX.

"full cone NAT" ... It is true that I don't see any reference about that on the pfsense. But I also see some people having no issue with firewall check and pfsense.

I'm complitly lost :) I will continue to read every post until the firewall check pass :)

Best reqards,
Christian Lambricht
 
Last edited:
OK, would you mind posting a screenshot to show your 3CX firewall rules from both pages of:
Firewall > NAT > Port Forward
and
Firewall > NAT > Outbound

I am a pfSense expert, we use over 200 of them, and more then half are used with 3CX.
 
Hi BrentG,


11805
Firewall > NAT > Port Forward
11802

Firewall > NAT > Outbound
11803
 
in pfSense the static port outbound rule is for your full cone nat ;)

Change to Hybrid Outbound NAT mode
Change rule for 5060 to be 5060-5061 (5061 is secure sip)
Change rule for 5001 to be 5000-5001 (5000 is legacy but some older phones use it, TCP only should be fine)
Change rule for 9000-10999 to be UDP only

Do any other rules use any ports within these same port ranges?
Do you have any other outbound rules besides 3CX rule, these may conflict.

Also this pfsense is on a really old firmware, there is a slight chance this could cause problems too, several years behind....

Also please post a new firewall check result
 
Last edited:
Same result

11806

Next step is to upgrade pfsense ....Do you have some advise? Is it easy?
 
what hardware is it running on? That is the million dollor question.
 
As i'm not on site at the moiment, I only have this info

11808

Other think maybe can be the issue is the server 2019 is runing on hyper-v 2016 server...

Best regards,
Christian
 
oh, hyperv.... I have seen that cause some "hinky" network issues in the past, but not sure.

It looks like the firewall might be a SG-2440, in which case, i recommend having a config backup and rescue usb ready as the jump to 2.4.x from so far behind, sometimes goes awry.
 
After reviewing the config, your NAT Outbound is a considerable mess, and it looks 99% superfluous, leave it set to Hybrid, and disable all of the rules in Outbound "EXCEPT" the 3CX rule at the top, and then try again and see if it makes a difference.
 
Also please confirm if there is anything on the 1-1 NAT page, or NPT pages, i am assuming there is nothing on them.
 
Status
Not open for further replies.

Forum statistics

Threads
111,933
Messages
589,809
Members
164,808
Latest member
jsbjsb