Cisco, Sonicwall & Fortigate Admins Required

Status
Not open for further replies.

N_G

Founder
Joined
Jun 6, 2006
Messages
4,849
Reaction score
9,253
Dear 3CX Community,

We are looking to update our Sonicwall, Cisco and Fortigate firewall configuration guides with the latest ports as well as how to configure Split DNS (also referred to NAT loopback or Hairpin NAT)

We dont have access to these devices in a production environment so if someone is familiar with these devices and would be able to update the guides it would be great. Of course we will pay you for your time. How it would work is that we would give you access to the Google Doc with the guide, and you can make the edits. Even if you are not a native english speaker its not an issue we will review afterwards.

Thanks in advance!
 
Hi @Nick Galea,

we can help with fortigate configuration for 3CX on cloud and on premise with split dns

Let me know if you're interested

Regards,
Valentin DEFREVILLE
 
I'd like to submit Ubiquiti for consideration as well for documentation on split DNS.
 
We can provide setup for opnSense and PfSense. The docs isn't fully up-to-date.

We also have Meraki if needed.
 
@ConceptsWeb
information for Meraki would be interesting.
Do you have a link about Split DNS and Meraki?
Thanks
 
  • Like
Reactions: N_G
@ConceptsWeb
information for Meraki would be interesting.
Do you have a link about Split DNS and Meraki?
Thanks
You cannot do Split DNS on Meraki (it has no DNS server) but I think it already does hairpin NAT automatically. You simply set your "internal" FQDN to the same as external. That's what we always do. Then DNS does the rest. If the IP is the same as the external IP, the Meraki reroutes internally directly. This obviously needs your port forward setup correctly.
 
  • Like
Reactions: N_G
We can provide setup for opnSense and PfSense. The docs isn't fully up-to-date.

We also have Meraki if needed.

@ConceptsWeb
information for Meraki would be interesting.
Do you have a link about Split DNS and Meraki?
Thanks

You cannot do Split DNS on Meraki (it has no DNS server) but I think it already does hairpin NAT automatically. You simply set your "internal" FQDN to the same as external. That's what we always do. Then DNS does the rest. If the IP is the same as the external IP, the Meraki reroutes internally directly. This obviously needs your port forward setup correctly.
We provided a standalone pfSense SplitDNS doc to 3CX already. Currently working on merging it into the general doc.
opnSense is a good one to do though

For Meraki regarding having built in DNS server, no, but also yes. It's not a documented feature, but support can enable it for you. It's super basic, but basically it will listen for any DNS register requests and then reply with those records. There are many limits to it, but it's there.
 
opnSense is a good one to do though
Yeah, it's almost the same as pfSense but does have some different UI stuff.

For Meraki regarding having built in DNS server, no, but also yes. It's not a documented feature, but support can enable it for you. It's super basic, but basically it will listen for any DNS register requests and then reply with those records. There are many limits to it, but it's there.
Oh wow! I did not know that! We only have a couple customers on Meraki and they both use internal AD DNS so I never needed to ask the support for that. I will now tho!
 
For Meraki regarding having built in DNS server, no, but also yes. It's not a documented feature, but support can enable it for you. It's super basic, but basically it will listen for any DNS register requests and then reply with those records. There are many limits to it, but it's there.
You have piqued my curiosity, do you know the exact name of the feature you have asked for get this small DNS resolver enable on Meraki ?
It could be a real workaround for some small installs with no internal DNS server !
 
You have piqued my curiosity, do you know the exact name of the feature you have asked for get this small DNS resolver enable on Meraki ?
It could be a real workaround for some small installs with no internal DNS server !
I would just tell meraki I wanted them to enable the internal DNS server...
 
  • Like
Reactions: N_G
Thank you all for your kind support! I am going to ask my colleague to reach out via PM and help me organize this.

So we will
Do a ione (thanks @pmterp )
Do a Meraki one (thanks @ConceptsWeb)
Do a Fortigate one (thanks @Valentin DEFREVILLE )
Pfsense one is on the way already (thanks @SweetAction)
 
Hi Nick, I've got your covered with Sonicwall. Pls give me a sense of your requested deadline.
 
  • Like
Reactions: MonikaR_3CX
@uptime1 perfect, will be in touch. over the next few weeks would be fine!
 
Thank you all for your kind support! I am going to ask my colleague to reach out via PM and help me organize this.

So we will
Do a ione (thanks @pmterp )
So sorry for the misunderstanding. I was meaning I'd love to see documentation made for Ubiquiti. I did not mean that I would be able to provide it.
 
@pmterp - no problem... OK i think based on the guides we will write it should be possible to figure how to do it for ubiquiti.

From a quick websearch it seems possible, see this Uibiquity Edgerouter Hairpin guide. They refer to it as hairpin NAT. Maybe you can go contact their technical support for questions.
 
Thanks all; I can provide assistance with Ubiquiti USG/DM and SonicWall firewalls.
 
  • Like
Reactions: MonikaR_3CX
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK