Firewall rules for VPN Strongswan

Status
Not open for further replies.

Evolute IT

3CX MVP
Gold Partner
Advanced Certified
Joined
Feb 6, 2018
Messages
11,209
Reaction score
7,033
Hi guys,

I came across a weird issue this morning: my VPN wouldn't come up. I tried several things (for hours) until I discovered that my IPTABLES rules were no longer there.

Why is that? I need to open some ports and ESP protocol to use Strongswan. It never did that before.

Is that a 3CX behavior? Is there a way to add our own rules?
 
VPN on the 3CX bad? That's bad mmmkay!
 
As above, VPN on the 3CX is not supported

https://www.3cx.com/docs/manual/installing-debian-linux-pbx/ - network , firewall & other requirement section

Unfortunately, it's my only option. My provider doesn't have a VPN service built-in and when I tried a pfSense instance to gather all VPNs, it was freaking slow.

It works very well as long as my IPTABLES doesn't reset or change. I have no issues at all except that one.
 
So if you are going to make changes, I suggest nuking the instance and doing a manual install on stock Debian instead of using the 3CX ISO. Once you start changing the environment that 3CX creates using their ISO you might as well be in a environment you fully control.
 
So if you are going to make changes, I suggest nuking the instance and doing a manual install on stock Debian instead of using the 3CX ISO. Once you start changing the environment that 3CX creates using their ISO you might as well be in a environment you fully control.

That would be an option. Apart from the IPTABLES, what does the 3CX ISO more than a manual install?

Also, their ISO sets up firewall rules that are really extensive.
 
Not really sure what the ISO does as I don't really use it. As for the firewall rules, unless you are on a VM with a public IP, you don't really need them unless you are trying to firewall from other internal resources. Lightsail/AWS/Azure/GCloud have their own firewall between your instance and 3CX.

If you are on a public IP I don't believe the 3CX ISO is doing anything more than what the regular firewall guide explains as far as opening ports. And you can always dump the ruleset from your current instance and just import it into your new instance. Then you have the firewall rules without worry about it automatically resetting them (assuming it was a 3CX ISO related script that did it in the first place).
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,932
Messages
589,806
Members
164,805
Latest member
Diana Paladutsa