Firewall checker detects incorrect ext ip

Status
Not open for further replies.

aaronalfa

Joined
Sep 30, 2014
Messages
1
Reaction score
0
I have a version 12 sp6.1 system I'm trying to setup and am having the following odd issues with the 3cx firewall checker:

the firewall checker fails all test because it incorrectly detects my external IP address, and I can't understand why.

Background:
-System has a public IP and hostname (pbx.company.com resolves to x.x.x.164)
-Watchguard Firebox has appropriate rules for all ports and dynamic masquerading nat from x.x.x.164 to the PBX internal IP. When I go to 'what's my ip etc' it shows the correct ext x.x.x.164 IP address.
-When I run the Firewall checker, it shows "resolved public IP x.x.x.166" The first part of the range is correct, but it should be 164 not 166.
-Under settings/network/STUN server I have the pbx.company.com in the "static public IP field"

I'm really stumped here. Any ideas what might be causing this incorrect resolution?
 
Did you do a check to see who does have that IP? Could you company be making use of multiple IPs that are managed by the router?

aaronalfa said:
-Under settings/network/STUN server I have the pbx.company.com in the "static public IP field"
I would put your domain name in the Domain Name field and your static public IP in the Static Public IP field.
You should be able to disable the use of STUN when using a static IP (in most cases).

Do external extensions register correctly?
 
I might be wrong when I say this, but I think a STUN server has to be used to check for 1-to-1 port mappings, meaning it will likely use your STUN server specified in the network settings even if a public IP address or domain name is used.

Do you still get the wrong IP if you bind port 3478 to x.x.x.164?
 
I do not think masquerading is needed. The settings within 3CX are setting up the STUN and SDP descriptors accordingly. As you have a fixed IP, I definitely agree with Leejor that the STUN setting in 3CX should not be needed. Set the firebox for 1 to 1 NAT and see. Also, if the SIP ALG is on, try with it off. Both functions - masquerading and ALG, have the ability to rewrite packets at the router.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,834
Messages
589,287
Members
164,664
Latest member
dominik.pepel