Firewall Test Failing - All ports confirmed as forwarding

Status
Not open for further replies.
Hi Lee,

You could consider co-locating the 3CX server and the main router.

Would that still work with the 3CX clients sitting behind the Inside-Router?

I'm also a little reluctant to have the 3CX Server sitting out in the open with the Outside-Router, but I guess it would look innocuous enough.



A better solution might be to use the ISP supplied router in modem / bridge mode, then you can use whatever router you like in partnership with it without worrying about double NAT or breaking ISP T&Cs / support arrangements.

This article might be interesting for you to have a look at: https://www.howtogeek.com/255206/how-use-your-router-and-isps-modemrouter-combo-in-tandem/
https://www.howtogeek.com/255206/how-use-your-router-and-isps-modemrouter-combo-in-tandem/

I'll have a look at that - I am not sure how that would dovetail with the other business, but I will investigate.

As a recent convert to 3CX I started with an on premise server but after trying a cloud deployment I simply wouldn't go back as it so neatly sidesteps lots of issues and is inexpensive.

Anything you do to work around the double NAT and continue with the additional routing is, unfortunately, going to be a bit of a kludge...

Yes - I can't disagree :-)

Thanks,

Alan.
 
Unfortunately, there is no practical way to get an ethernet connection from the 3CX Server to the Outside-Router. There is only one cable run, which is already running to the Inside-Router, else I would definitely go wired if I could.

Can you just run the ethernet cable that is going to the WAN of the inside router into a small 5 port switch and then plug the inside router WAN and the 3CX box in ? Or am I not understanding the setup?
 
Hi cobaltit,

Can you just run the ethernet cable that is going to the WAN of the inside router into a small 5 port switch and then plug the inside router WAN and the 3CX box in ? Or am I not understanding the setup?

Yes - we could do that, but as I said above, I'm also a little reluctant to have the 3CX Server sitting out in the open with the Outside-Router.

I will have to talk to my client, but currently that is where I am heading.

Thanks,

Alan.
 
What 'open' are you talking about? It's behind the outside router so there is still a NAT layer between it and the internet and wouldn't be any more open to the internet than you already tried to accomplish with the port forward you were trying to do. It would be slightly more open to the other company sharing your internet but that's about it.
 
Hi cobaltit,

What 'open' are you talking about? It's behind the outside router so there is still a NAT layer between it and the internet and wouldn't be any more open to the internet than you already tried to accomplish with the port forward you were trying to do. It would be slightly more open to the other company sharing your internet but that's about it.

I mean in a physical sense - it will be sitting out in the open in the shared space just inside the front door, rather than in a 'server room' (actually an unused office) in my client's space.

I'm not concerned about it in a network security sense.

Thanks,

Alan.
 
Ahh ok that makes more sense :). Well good luck with whatever option you go with!
 
Status
Not open for further replies.

Forum statistics

Threads
111,913
Messages
589,706
Members
164,783
Latest member
GothamUser