Firewall Checker fails

Status
Not open for further replies.

Sully

Silver Partner
Basic Certified
Joined
Mar 19, 2019
Messages
20
Reaction score
7
Hello all!

We are doing a proof of concept for a new install. They installed the debian version ISO on a VMWare Server. We couldn't get the firewall checker to pass after configuring the firewall which is a Fortinet. Mapping errors are attached. If feels like a NAT issue, but wanted to see if anyone has seen these mapping errors before on a Fortinet. We have a case open with Fortinet and initially they said everything looks right from a config perspective but we are escalating. At the moment, everything seems to be working ok other than provisioning phones (yealink) on the local LAN is taking longer than normal (5-10 minutes).

Thanks!
 

Attachments

  • forti.png
    forti.png
    55.8 KB · Views: 17
I saw that issue once, the IT provider had to disable the SSL Deep Inspection setting. I don't know how and where but it worked well !
 
I had the same issue when setting up our 3cx a while back. it was a setting on my Pfsense firewall, which was changing the outbound port. i read the firewall config document, and then the 3cx passed all the tests.
 
Indeed some level of NATing is occurring. You want to enable full cone NAT and have port preservation and also make sure that SIP ALG or SIP Helpers etc are disabled on your firewall.
 
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,818
Latest member
Guriqbal Singh