Failing firewall tests after upgrading to v16 but everything works fine.

Status
Not open for further replies.

TPR3CX

Customer
Joined
Dec 13, 2018
Messages
88
Reaction score
6
Greetings,

When we deployed 3CX on v15.5, we passed all the firewall tests among all other issues. When we upgraded to v16, we now fail the firewall tests even though we did not make any changes.

Any ideas? I'm posting the output below.


resolving 'stun-us.3cx.com'... done
resolving 'stun2.3cx.com'... done
resolving 'stun3.3cx.com'... done
resolving 'sip-alg-detector.3cx.com'... done
testing 3CX SIP Server... failed (How to resolve?)

stopping service... done
detecting SIP ALG... not detected
testing port 5060... full cone test failed (How to resolve?)
starting service... done

testing 3CX Tunneling Proxy... done

stopping service... done
testing port 5090... done
starting service... done

testing 3CX Media Server... failed (How to resolve?)

stopping service... done
testing ports [9000..9398]... failed (How to resolve?)
testing port 9000... full cone test failed (How to resolve?)
testing port 9002... full cone test failed (How to resolve?)
testing port 9004... full cone test failed (How to resolve?)
testing port 9006... full cone test failed (How to resolve?)
testing port 9008... full cone test failed (How to resolve?)
testing port 9010... full cone test failed (How to resolve?)
testing port 9012... full cone test failed (How to resolve?)
testing port 9014... full cone test failed (How to resolve?)
 
What kind of Firewall?
 
Firewall is remapping the audio ports, in other words, not following consistent nat principles, depending on the firewall, this is correctable, what firewall model, and firmware version.
 
When you say you didn't make any changes, do you mean configuration changes? What about software/firmware upgrades?
 
So you restricted ports to 3CX FQDNs? That's not the default setup so it would have been helpful to include that information in your initial post. Also the firewall checker is just a tool to check for problems. It doesn't create problems where none exist. If everything works you're all good
 
Last edited:
  • Like
Reactions: PvK
Give your firewall a restart. There may be some routing issue there.
 
FIrewalls are Cisco ASA 5525X. We passed on v15.5, but failing on v16.x. Meanwhile everything has been working fine. I was discussing this with my engineer and we would like to know what the range of IPs are for 3CX so we can make sure we have them open properly.
 
I uses the 3CX STUN servers but their IPs may change from time to time.

If you are just blocking traffic from all but known source IPs then the checker will fail but will not necessarily mean it will cause you issues.
 
Where can I find the latest IP ranges for the 3CX STUN servers? We looked an article somewhere and it mentioned just opening the ports up to the whole world which is something we're not keen to doing.
 
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,819
Members
164,811
Latest member
aurorasigntrtechitnet