Firewall Test Fails

Status
Not open for further replies.

Chris Bell

Free User
Joined
Mar 7, 2018
Messages
20
Reaction score
0
Hi ,

We have configured our system passing through a SRX Juniper firewall. We have SIP ALG disabled and have configured a one to One NAT. The firewall test results in "Full Cone NAT" errors. a one to one NAT is full cone. Anybody else had this issue ? everything seems to works. We do have some call quality issues in conference calls, but all calls succeed OK.

  • resolving 'stun-eu.3cx.com'... done
  • resolving 'stun2.3cx.com'... done
  • resolving 'stun3.3cx.com'... done
  • resolving 'sip-alg-detector.3cx.com'... done
  • testing 3CX SIP Server... failed (How to resolve?)
    • stopping service... done
    • detecting SIP ALG... not detected
    • testing port 5060... full cone test failed (How to resolve?)
    • starting service... done
  • testing 3CX Tunneling Proxy... done
    • stopping service... done
    • testing port 5090... done
    • starting service... done
  • testing 3CX Media Server... canceled
 
Thanks for those we have read them , and cant really work out the issue. The polices check out the first error is 3CX SIP server that fails testing port 5060, the the media server fails. Here are the port configs if it helps.

term 1 alg ignore protocol udp destination-port 5060;
term 2 alg ignore protocol tcp destination-port 5060;
term 3 alg ignore protocol tcp destination-port 5061;
term 4 alg ignore protocol udp destination-port 3478;
term 5 alg ignore protocol tcp destination-port 5090;
term 6 alg ignore protocol udp destination-port 5090;
term 7 alg ignore protocol udp destination-port 9000-9500;
 
Hello @Chris Bell

If you take a look at the Firewall checker guide you can see that you can use wireshark along side the firewall checker to determine the issue. You should get the same results in both.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,885
Messages
589,547
Members
164,745
Latest member
Herm77