Firewall Checker

Status
Not open for further replies.

forrestdean

Premier Customer
Joined
Mar 28, 2019
Messages
26
Reaction score
3
Just out of curiosity, is the firewall checker a reliable test, because half the time I get success and half the time it fails most of the checks. I've been using 3CX for almost a year now and the entire phone system works great. So far I have no problems, and all communications are working. However, from time to time I run a firewall check just to make sure communications are working as they should be and sometimes I get a complete success and other times I get failures all over the place. So I'm wondering if the firewall checker is even relevant or a reliable test.

It was helpful in the beginning when I first set up the phone system. But looking back now, I'm wondering when I received so many failures while setting up the phone system if I, in fact, had any misconfigurations at all.

Or could there actually be something configured wrong on the firewall? Again, the entire phone system is working great. I'm running a Palo Alto PA-3020 firewall and I've checked over the firewall policies over a dozen times and they are all configured correctly. Since everything is working correctly, maybe I should just forget about the firewall checker and never run it again. However, that makes me kind of nervous if there are any communication problems in the future I won't know whether to use the firewall checker or not and if I do I won't know if it's telling me correct results or not. It might be better to just use Wireshark in the future if any problems arise.
 
So the firewall checker is a tool nothing more. It's fairly reliable, although when there have been incidents 3CX is usually slow to confirm them. There's also been small quirks with some versions but no issues with either v15.5 Update 6 or v16 Update 2 that I'm aware of. It's likely your Palo Alto to blame. You may have all the rules in place but often your UTM type devices will see the firewall checker as an attack and defend against it. Not sure if you can check the logs to see if that's what is happening.
 
Ok, so I figured out why my firewall checker is failing at the moment. I have a firewall policy currently in place that allows outbound Internet traffic only to the US region. All other regions are blocked. However, whenever I create another policy allowing my 3CX server outbound to all regions my firewall checker passes successfully. I would prefer not to allow any outbound traffic to all regions for security purposes, so:

Does anyone know the exact IP address the firewall checker is communicating with so that I can add those IP addresses to my white list?

Thank you very much for your help with this.
 
Hi @forrestdean

I think you already answered the reason for yourself with the region blocking. The checker will work if the rules are set up for the traffic the system expects to be able to use. It runs the checks against our own servers but there's no specific set of IPs, because they can change from time to time and from region to region and you might not end up on the same server every time. If you wish to ensure the check passes, keep your rules but disable blocking by region during the test and see.
 
Good point. I think that's what I will do. Thank you for the response.
 
Status
Not open for further replies.

Forum statistics

Threads
111,933
Messages
589,813
Members
164,808
Latest member
jsbjsb