Firewall Checker fails on a few media server ports

Status
Not open for further replies.

JMK

Bronze Partner
Basic Certified
Joined
Jan 2, 2018
Messages
49
Reaction score
4
Anyone experience this issue before? (images attached)

Firewall Checker is passing everything but a few Media Server ports 10794 – 10824. This failed port range is consistent, however occasionally one of the failed ports in that range will pass.
The error on the ports is “full cone test failed” which is NAT related. It makes no since NAT is fine on every port except these few.

Zyxel USG20-VPN Firewall
1:1 NAT

AT&T Uverse – I’ve never used it before and it was a challenge to get the gateway (Arris BGW210) to truly get out of the way of the firewall. They use “Pass-Thru” not a true bridge mode. After doing some tweaking if seems to be working.

3CX version 16.0.5.619

Everything is new, Internet service, equipment and 3CX installation.

Additional Info:
Debian 9 On-Premise
Yealink T23G - working fine
All local auto-provisioning - working fine
Flowroute - Working fine
 

Attachments

  • 1.JPG
    1.JPG
    43.6 KB · Views: 5
  • 2.JPG
    2.JPG
    61.5 KB · Views: 6
  • 3.JPG
    3.JPG
    57.8 KB · Views: 6
Last edited:
Hi JMK,

Being behind 2 NAT devices can be a pain, so in your place I would bypass the firewall entirely and see if I can replicate the issue on the Arris box first.

Once you eliminate which of the two boxes is the likely cause, you can focus on it. But with two "unknowns" in the pipeline it will not be easy to track down the cause.

1. Use the PBX as the "Passthrough" device (not your Zyxel)
2. Run enough tests to the point you're happy the problem has gone away
3. If the Arris passes, then you know the Zyxel is the likely cause
4. If it does not, then you may have to talk to your provider.

- Search the forum, you will find other threads referring to Uverse and you might get some additional insight.

- Search Google for "3cx uverse" to get additional results that might not pop up in the forums search box
 
Make sure that sip alg on zyxel usg20 is disabled. You don't need to do 1:1 nat. If your att modem pass public ip address to zyxel then you should not have any problem with that.
 
Status
Not open for further replies.

Forum statistics

Threads
111,956
Messages
589,927
Members
164,858
Latest member
MichaelRussell3