Fail on 3CX Firewall Check Fortigate 60E

Status
Not open for further replies.

advlaser

Forum User
Joined
Oct 27, 2013
Messages
60
Reaction score
6
We've been on a Fortigate 60E for over a year now with no problems. Always passed the Firewall Check. On Tuesday our phone system went down and we are getting no phone calls in or out. The SIP trunk still registers fine but the firewall check now fails. We've gone over the Fortigate and quadruple checked that SIP ALG is disabled and that all of the settings related to that are disabled and correct with a Fortigate engineer. So why is this failing?

But when we run the Firewall Check we get this.
  • resolving 'stun-us.3cx.com'... done
  • resolving 'stun2.3cx.com'... done
  • resolving 'stun3.3cx.com'... done
  • resolving 'sip-alg-detector.3cx.com'... done
  • testing 3CX SIP Server... failed (How to resolve?)
    • stopping service... done
    • detecting SIP ALG... failed (How to resolve?)
    • testing port 5060... full cone test failed (How to resolve?)
    • starting service... done
Is the firewall check independent of the SIP provider? Just wondering if AT&T (my SIP) provider had a problem, could it affect the Firewall Check? So far the support from AT&T has been dismal. Thanks! Marvin
 
Hi Marvin,

SIP ALG failed = the test could not be completed, so it remains unknown if ALG is enabled

SIP ALG detected = you have SIP ALG enabled

Since the full cone test failed and the ALG test also failed, I'm wondering whether you are blocking the 3CX stun servers (they are the ones used in the test, not your SIP provider). The test says they are resolved, but it does not mean they are reachable. You may have to run a firewall check again, while running a capture from your Fortigate and from your PBX to compare the traffic (does everything the PBX sends pass through your WAN interface and back?)
 
Are you on a current firmware with the 60E? Follow these instructions to a T:

https://www.3cx.com/docs/fortigate-firewall-configuration/

If you are on 6.2.X firmware, your code will look something like this under step 1:

config system settings
set sip-expectation enable
set sip-nat-trace disable
set default-voip-alg-mode kernel-helper-based
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,948
Messages
589,880
Members
164,841
Latest member
erre