Detecting SIP ALG... failed and the Port 9000 full cone test Failed

Status
Not open for further replies.

Fred-E

Free User
Joined
Jan 18, 2023
Messages
8
Reaction score
0
  • 3CX Version: 18.0
  • Server OS: Debian 3CX hosted on Windows server 2016 Hyper-V on premise
  • Has the Firewall Checker passed: No
I am trying to figure out this issue since 2 weeks and got some ideas about the problem. First of all I have configured the firewall of the router more than 5 times and I don't have any other firewalls. My router is a D-link DIR-825 and I have SIP ALG disabled. As per wireshark captures I can see when I run the Firewall checker, a request is sent to 34.141.156.185 ip through port 5060. But the response isn't received. I'm not sure if the response is not coming through or the request is not going through. When I removed the port forwarding configuration for port 5060, the packets captured remains the same. I believe the reason for port 9000 to fail is because the SIP ALG detector fail.
1678461519188.pngdoes anyone have any idea how I can resolve the issue?

Thanks in advane.
Regards,
Fred-E.
 
Yes I have an ISP modem in front of the D-Link. But I've contacted the ISP and asked them to remove the restrictions if there are any. After that the ports were released and testing of ports are OK. I don't know if I have to specifically tell them to remove SIP ALG. I will contact them again.
 
Support for the 825 ended in 2015...if you have a PC with two NICs you might want to try pfSense, or another router from
https://www.3cx.com/support/firewall-configuration/.
I would rather prefer using a router instead of pfSense. The reason is I should get gigabit NICs for speed of the network and I should set up a PC which will be running 24hours. Can you suggest some good routers that I can buy out there which is supported by 3cx. Additionally I would like to setup a captive portal for my wifi hotspot, so I need the router to support that also. Will the MikroTik Routerboard - RB750Gr3 fulfill my requirements?
Any help is much appreciated.

Regards,
Fred-E
 
Well Netgate sells many routers that aren't full PCs.I just threw it out because it would be easy to set up and test. And it does have a captive portal, though doesn't integrate Wi-Fi directly.

MikroTik is on that web page. I'm not familiar with their capabilities.
 
Hi,
So I set up pfSense and configured. Everything works but this issue is still there. I did the port forwardings, I reconfirmed with the ISP if there is any firewall from there side, they told me they have enabled DMZ on their router so no ports are blocked and there are no limitations from their side. In fact we have several IP Phones managed by the ISP via cloud PBX which are connected to the same network. They are working fine. I have captured the packets using pfSense also, All the requests get response only the request sent to the SIP ALG Detector (34.141.156.185) doesn't get response.
 
Hi,
So I set up pfSense and configured. Everything works but this issue is still there. I did the port forwardings, I reconfirmed with the ISP if there is any firewall from there side, they told me they have enabled DMZ on their router so no ports are blocked and there are no limitations from their side. In fact we have several IP Phones managed by the ISP via cloud PBX which are connected to the same network. They are working fine. I have captured the packets using pfSense also, All the requests get response only the request sent to the SIP ALG Detector (34.141.156.185) doesn't get response.
See this: https://www.3cx.com/docs/pfsense-firewall/#h.2jgg3u44tw29
 
  • Like
Reactions: jed
These are the packets captured.
1679400360922.png
Only the requests are sent but the responses aren't received.
 
Status
Not open for further replies.

Forum statistics

Threads
111,972
Messages
590,065
Members
164,887
Latest member
KrishnaMR