firewall options in same machine

Status
Not open for further replies.

surenr

Customer
Joined
Apr 1, 2019
Messages
47
Reaction score
10
dear team,

posting this after searching the forums,

is anyone here using a firewall solution(block/allow ip ranges/addresses) in the same 3cx on-premise machine? without any vms ? runnning along side 3cx in the debian os ?

nftables not installed by default but will be installed by ufw.
so easiest to start with is UFW, or Uncomplicated Firewall and iptables is there but is it ok use it in the same machine ?
i mean will it affect call quality? mobile apps ? 3cx tunneling?

when i try to enable ufw its throwing error so stuck there also .
root@fmf3cx:~# sudo ufw enable
Command may disrupt existing ssh connections. Proceed with operation (y|n)? y
ERROR: problem running ufw-init
iptables-restore v1.8.2 (nf_tables):
line 3: CHAIN_UPDATE failed (Operation not supported): chain INPUT


if so could you share your experience and what software packges you use and any recommendations ?

thanks in advance.
 
Last edited:
iptables and nftables not installed by default.
Are you still using Debian 9 like your signature suggests? On Debian 10 with the 3CX V18 deployment, nftables are in use.

On systems we host, we limit SSH to our own IP space. See this post for more info.
 
  • Like
Reactions: Evolute IT
Actually, if you install using supported methods (Deployment Wizard, Marketplace or ISO), it does install nftables and configure it for only the 3CX ports.
 
  • Like
Reactions: Nathan@Voxtelesys
hi guys, thanks for the replies

yes im on Debian 10 with the 3CX V18 installed by the iso

i run below command

sudo systemctl enable nftables.service

and this

root@fmf3cx:~# systemctl status nftables
● nftables.service - nftables
Loaded: loaded (/lib/systemd/system/nftables.service; enabled; vendor preset: enabled)
Active: active (exited) since Fri 2023-03-10 12:30:31 IST; 5min ago
Docs: man:nft(8)
http://wiki.nftables.org
Process: 284 ExecStart=/usr/sbin/nft -f /etc/nftables.conf (code=exited, status=0/SUCCESS)
Main PID: 284 (code=exited, status=0/SUCCESS)

Mar 10 12:30:31 fmf3cx systemd[1]: Started nftables.
Warning: Journal has been rotated since unit was started. Log output is incomplete or unavailable.

from above i understand 3cx is directly starting nftables and i dont need to enable.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet