Firewall errors after install of V20

DGZ

Customer
Joined
Oct 30, 2019
Messages
6
Reaction score
7
Hi all,

I just did the upgrade from V18 to V20. After doing this, the system appears to be working but when I run the firewall check, I get the following errors. Everything was working successfully on V18. Not sure if this makes a difference but when I did the install, I forgot to change the port of the HTTP/HTTPs so uninstalled and reinstalled (and restored back again), this time changing the port to what the V18 was using and what is in the Firewall settings.

These are the firewall errors:
detecting SIP ALG... detected (received c684090d ≠ 0910eab9)
testing 3CX PhoneSystem Media Server... failed
testing ports [9000..9398]... failed
testing port 9000... full cone test failed


We are running on a Windows 2016 Server through a Sophos firewall. Split DNS is enabled on domain server. I can access web console without any issues.

From the Dashboard:
Current version - Version 20.0 Update 6 (Build 724 Release)
Network PortsSIP:5060SIPS:5061Tunnel:5090Media:9000-10999HTTP:5000HTTPS:5001
All these ports are open and working (to my knowledge) on the server

We can make calls, receive calls, apps work on devices so not sure what is actually happening here.

Thanks
Dean
 
Check if the ports are open to “any” on the Windows firewall.

ALG would be the router though.
 
  • Like
Reactions: DGZ
Hello @DGZ ,

You will have the Windows firewall and the WAN Sophos firewall.

For Windows, this is fine:
Ports:
SIP:5060 UDP
SIPS:5061 TCP
Tunnel:5090 UDP and TCP
Media:9000-10999 UDP
HTTP:5000 TCP
HTTPS:5001 TCP

For the Sophos, please use:
Ports:
SIP:5060 UDP (only for provider!)
SIPS:5061 TCP (only for provider!)
Tunnel:5090 UDP and TCP
Media:9000-10999 UDP
HTTP:5000 TCP (Block!)
HTTPS:5001 TCP
Make sure you have the ALG off in the router.

Also please read this page on Firewall setup.
https://www.3cx.com/docs/manual/firewall-router-configuration/

Paulo
 
  • Like
Reactions: DGZ
Thanks Steve and Paulo

I had completely forgotten about the Windows Firewall - will check that and see if that fixes the issues. I will double check the ports and ALG on the Sophos - nothing changed from the Ver18 but this is IT so who knows.

Thanks again for the help - will let you know how it goes.

Dean
 
Hi Steve and Paulo

Apologies for the delay getting back to this - had a few other issue come up. I have checked both firewalls and they all appear to be OK. It is all the same as I set when running V18 and matches the information you have given me. I have also disabled TCP5000 as per your recommendation Paulo - thank you for that.

I don't have a specific LAN to WAN rule on the firewall so am checking Sophos forums to see if that is required.

I still get the same same errors but the phones have been working perfect since the update. I can't find ALG details in the sophos firewall - not sure if they don't exist or I just can't find them - will work on that but otherwise it is a mystery.

Thanks again for the help and suggestions - I will keep working on this and let you know.

Thanks
Dean
 
Hello Dean,

Found this with Google, about the Sophos:

1000010447.jpg
Hope it will help you.

Paulo
 
Hi Paulo,

Thank you for that - I was check the web interface - did not even think about the console (rookie mistake) - have logged into the console and made this change but can't test now as phones are in use. Will check later and see if that makes the difference.

Appreciate you finding the letting me know this.

Thanks
Dean
 
  • Like
Reactions: paulodagraca
Wow, talk about feeling like a rookie! Yep that fixed the issue - ALG turned off and firewall now reporting no issues.

Really strange part is that it worked perfect in Ver18 - no firewall errors but ALG was turned on - guessing something in the V20 update is a bit more particular in the checking.

Green tick on firewall - happy days!

Thanks for the assist Paulo and Steve