External IPs to be allowed through firewall

Discussion in '3CX Phone System - General' started by LWP, Feb 27, 2017.

Thread Status:
Not open for further replies.
  1. LWP

    LWP

    Joined:
    Dec 9, 2016
    Messages:
    4
    Likes Received:
    0
    Hi Guys
    Do I need to allow the traffic from any other ips than my voip provider? When I lock the policy down to my provider's ip the firewall check fails on "testing 3CX SIP Server" with "full cone test failed", when I allow all sources on the firewall the test passes. Calls are working regardless.
    I have looked at documentation but can't find the answer.
    thanks
     
  2. eagle2

    eagle2 Well-Known Member

    Joined:
    Apr 27, 2011
    Messages:
    1,085
    Likes Received:
    11
    If you don't use external extensions (or VoIP providers), you don't need to allow new traffic through your inbound connections firewall.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. LWP

    LWP

    Joined:
    Dec 9, 2016
    Messages:
    4
    Likes Received:
    0
    the mentioned "provider" in my post is a Voip provider. When I only allow their ip firewall check fails.
     
  4. GiannosC_3CX

    GiannosC_3CX Guest

    Hi LWP,

    Please note some providers send the RTP through differed servers, so if you allow only your provider, also you need to allow all the RTP servers used by your provider.
    May I refer on this link https://www.3cx.com/blog/voip-howto/static-port-mappings/ you can find all the relevant details why "full cone test failed".
     
  5. craigreilly

    craigreilly Well-Known Member

    Joined:
    Feb 1, 2012
    Messages:
    3,424
    Likes Received:
    277
    and firewall test will fail - as you are not allowing traffic from the testing servers.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Thread Status:
Not open for further replies.