Firewall check is failing

Status
Not open for further replies.

JSlow

Free User
Joined
Apr 8, 2020
Messages
29
Reaction score
7
Hello,

We have a Sonicwall and I have configured it according to these guides:
https://www.3cx.com/docs/manual/firewall-router-configuration/
https://www.3cx.com/docs/sonicwall-firewall-configuration/

However, when I run the firewall test the ports are being "remapped". I have verified that the option to NOT remap ports is checked. I even called and had them verify. We were able to verify that outgoing ports are not being remapped and are remaining the same but 3CX is reporting something different.Verification was done using the packet trace in sonicwall.

Has anyone had this issue with sonicwalls? Mainly the NSA 3600.
I don't want to open a support ticket because I'm trying to pitch this and having to pay to get a working demo is not a good start for that...
 
So opening a ticket won't help as this is not a 3CX issue, this is a Sonicwall issue. Sonicwalls are notoriously a PITA as far as VoIP and I know many partners rip them out when they can. Personally I've never configured one but I can say from experience that anytime we've had a customer's IT make the necessary changes it usually takes them 2-3 tries before they get it right. The usual culprit is outbound NAT settings. Any chance of putting it in a VM and using a SBC (if you have local physical phones). Then you'd have zero firewall changes needed
 
So opening a ticket won't help as this is not a 3CX issue, this is a Sonicwall issue. Sonicwalls are notoriously a PITA as far as VoIP and I know many partners rip them out when they can. Personally I've never configured one but I can say from experience that anytime we've had a customer's IT make the necessary changes it usually takes them 2-3 tries before they get it right. The usual culprit is outbound NAT settings. Any chance of putting it in a VM and using a SBC (if you have local physical phones). Then you'd have zero firewall changes needed
It's already in a VM. I can just re-install as a SBC. But you make it sound like an SBC doesn't have the web-client. Is that true? The idea of me demoing 3CX is to show its web-conferencing and its soft-phone feature without paying more for them.

To be honest, I was trying to find the difference between the normal client and a SBC but I couldn't get any solid answers. So if you have a brief explanation that would help also. Thank you.
 
Have you triple checked for SIP ALG? has a funny habit of re-mapping ports as it feels fit.
 
What firmware is your SonicWALL using? I use them exclusively at my client sites without issue and find them to be very easy to troubleshoot.
 
So if you are strictly testing/demoing the web client the the firewall checker is probably not necessary to pass. As long as 443/5001 inbound and 9000-10999 inbound is forwarded I'd ignore the firewall checker for now and just test web meeting. Or just follow this for testing:

https://www.3cx.com/docs/hosted-pbx-google-cloud/

If you like it, you can look at moving it to your own cloud of choice or with a 3CX provider that does hosting (like us).

For the SBC, that's just a piece that helps phones traverse firewalls. Not needed for the web client or soft clients, only hard IP phones.
 
Status
Not open for further replies.

Forum statistics

Threads
111,943
Messages
589,860
Members
164,833
Latest member
Edal