Solved Brand New Sonicwall TZ 600, Windows V16, wierd media ports random failure

Status
Not open for further replies.

microsystems

Silver Partner
Joined
Feb 1, 2013
Messages
20
Reaction score
8
Just delivered a new system , using a Sonicwall TZ 600 w/ latest10126 SonicOS, 6.5.31-48n 3cx V16 running on server 2016. up to date on 3cx patches. When I run the firewal checker, a copule of the rtp ports randomly fail as seen in the picture. Standard sonicwall NAT setup as we have done on dozens of other Sonicwalls.10127


only using a single static, and yes I do have source port remapping disabled. the ports it fails on are random, sometimes one, sometimes more than one.

Anybody ever see this? Works fine otherwise.

Jeff
 
Is SIP ALG disabled in the SonicWall?

Are you using a 1:1 NAT?
 
Hello @microsystems

Please note that we have identified an issue with the firewall checker in V16 which can falsely fail a few RTP ports in certain scenarios. If you are only failing a few RTP ports with the "mapping does not match"
message then i would recommend ignoring them for now until the issue has been resolved.
 
  • Like
Reactions: Evolute IT
Yes, of course SIP ALG is disabled, actually we have been seeing it disabled by default but we check anyways. Sonicwall dropped 1:1 NAT and it is done thru policies now, but I do have the standard NAT policies for the 3cx services. I am starting to see others reporting this glitch with V16 installs on the forums here, I am going to take some WS traces and look at them. It may be just some timing bug on the Firewall Test.

jeff
 
  • Like
Reactions: Evolute IT
Yes, of course SIP ALG is disabled, actually we have been seeing it disabled by default but we check anyways. Sonicwall dropped 1:1 NAT and it is done thru policies now, but I do have the standard NAT policies for the 3cx services. I am starting to see others reporting this glitch with V16 installs on the forums here, I am going to take some WS traces and look at them. It may be just some timing bug on the Firewall Test.

jeff

Like @YiannisH_3CX said, probably the firewall checker bug.
 
Hello @microsystems

Please note that we have identified an issue with the firewall checker in V16 which can falsely fail a few RTP ports in certain scenarios. If you are only failing a few RTP ports with the "mapping does not match"
message then i would recommend ignoring them for now until the issue has been resolved.
Thanks, YiannisH,

That is what I thought, but didnt want to go into production at that site and have audio issues. Thanks for looking into it.

jeff
 
Thanks, YiannisH,

That is what I thought, but didnt want to go into production at that site and have audio issues. Thanks for looking into it.

jeff
Please mark this thread as "solved"!
 
  • Like
Reactions: YiannisH_3CX
I have actually seen this with a sonicwall TZ unit. Everything works fine but 3CX will claim that it is mapping to a different port. I have also seen it with multiple systems behind one sonicwall and multiple WAN IP addresses. Running the firewall checker only one system will test OK. The others have that odd mapping error.

Can't find a reason why. SIP ALG settings are correct and all ports map with a 1:1 NAT
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,918
Messages
589,737
Members
164,792
Latest member
LBS Care