Solved Firewall Checker error message in 3CX PBX

Status
Not open for further replies.

PeterCheng

Forum User
Joined
Jan 5, 2021
Messages
105
Reaction score
11
Hello sir,

We adopted 3CX as new UC solution POC recently, and right now everything seems right except th firewall checker result in 3CX web console.
Though our 3CX PBX works normallt and it seems nothing strange, but its firewall checker cannot fully pass in our environmnt.
I also have a 1-to-1 NAT for the server.
I'm wondering where the 3CX firewall checker is checking? From firewall I don't see any drop message.
Would somebody kindly tell me its mechanism for checker, what does it do? Thanks.

Peter
1623210456419.png
 
Here is a good article from 3CX on the built in firewall checker. https://www.3cx.com/docs/firewall-checker/ It uses their STUN servers to check the port forwarding and to ensure the ports aren't being remapped.
 
  • Like
Reactions: PeterCheng
Is this a sonicwall?
 
I won't be able to help with Palo Alto as we exclusively use SonicWall for our customers. You may want to reach out to Palo Alto support for this as it could be SIP ALG or need other rules/NAT policies to avoid remapping.
 
I won't be able to help with Palo Alto as we exclusively use SonicWall for our customers. You may want to reach out to Palo Alto support for this as it could be SIP ALG or need other rules/NAT policies to avoid remapping.
Hello jcostlow,
Thanks for your feedback.
I believe that it's our PA FW issue, becasue I can see lots of packets were dropped by our FW (it should be the test packets coming from 3CX stun server). I researched 3cx document about firewall checker test procedure, and so-called test1 was okay, test2 was failed. 3CX pbx will send request to its stun server, and it will intentionally change to another ip for the response. PA treated these response packets as abnormal behavior and then dropped them.
We will think about such behavior and how to avoid the check mechanism in the PA FW, thanks.

Peter
 
  • Like
Reactions: ChrisC_3CX
@PeterCheng
You've probably already done this but do make sure that all inbound traffic to all 3CX required ports is allowed from any source, because, as you correctly said, the firewall checker will deliberately respond from a different IP and from a different port and that is the specific test yours seems to be failing.
 
  • Like
Reactions: ChrisC_3CX
@PeterCheng
Excellent! Glad to hear you've resolved this!

Please feel free to start a new thread should you require additional information or assistance.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet