- Joined
- Jun 24, 2014
- Messages
- 7
- Reaction score
- 0
Just need a little clarification as to how firewall rules should be set up.
I have a Juniper SSG 140. I have disabled SIP ALG.
I have a MIP that is mapped to my private IP.
I have created a service that allows the required ports as per http://www.3cx.com/docs/firewall-router-configuration-voip/. So i have an inbound rule allowing 5060, 5000 and 9000-9049 (UDP and TCP where required as per doco).
When i log this rule, the only traffic that hits it is port 5060.
Its not until i create an outbound rule for any destination, any source on any port that i get audio, and when i log that rule, calls are using random ports above 19000, or they appear to start on the correct port but get translated when hitting the destination (See attachment).
Should it be going out within the 9000-9049 range?
Have i missed something in terms of my firewall config to stop the ports getting translated to something above 19000, or is this behavior to be expected?
Is the expectation that you need an outbound any/any rule for 3cx, as it is not listed on the link for firewall config?
I'd really like to be able to lock this server down so that only the required ports are open in and out and I can't seem to get that to work due to the higher port range handling the call.
Any help would be appreciated.
cheers
I have a Juniper SSG 140. I have disabled SIP ALG.
I have a MIP that is mapped to my private IP.
I have created a service that allows the required ports as per http://www.3cx.com/docs/firewall-router-configuration-voip/. So i have an inbound rule allowing 5060, 5000 and 9000-9049 (UDP and TCP where required as per doco).
When i log this rule, the only traffic that hits it is port 5060.
Its not until i create an outbound rule for any destination, any source on any port that i get audio, and when i log that rule, calls are using random ports above 19000, or they appear to start on the correct port but get translated when hitting the destination (See attachment).
Should it be going out within the 9000-9049 range?
Have i missed something in terms of my firewall config to stop the ports getting translated to something above 19000, or is this behavior to be expected?
Is the expectation that you need an outbound any/any rule for 3cx, as it is not listed on the link for firewall config?
I'd really like to be able to lock this server down so that only the required ports are open in and out and I can't seem to get that to work due to the higher port range handling the call.
Any help would be appreciated.
cheers