Firewall test

Discussion in '3CX Phone System - General' started by Mark Drabble, Mar 15, 2018.

Thread Status:
Not open for further replies.
  1. Mark Drabble

    Joined:
    Nov 13, 2017
    Messages:
    14
    Likes Received:
    0
    I have installed 3cx using an external static ip x.x.x.85 and I can ping domain.3cx.co.uk and it resolves to the correct ip address.

    When I run the firewall test, it fails on the port tests.

    I've monitored my firewall and I can see the traffic hitting my gateway address x.x.x.10 (which is where my traffic goes through) and not the ip address I assigned to the 3cx server x.x.x.85

    I'm using a smoothwall UTM for my firewall.

    Anyone any ideas what I can do to get the port tests to resolve to the correct ip.
     
  2. craigreilly

    craigreilly Well-Known Member

    Joined:
    Feb 1, 2012
    Messages:
    2,997
    Likes Received:
    190
    1) Windows firewall disabled?
    2) What ports are failing?
    3) Have you configured all rules for TCP and UDP?
    https://www.3cx.com/docs/manual/firewall-router-configuration/
    4) Disabled SIP ALG if it exists in the router? or VOIP Network protection?
    5) I always setup an SNAT - Internal Static 3cx Server IP - Masquerade as External 3cx Static IP. This reflects outbound traffic on that machine goes out as the .85 and not the default .10.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. Mark Drabble

    Joined:
    Nov 13, 2017
    Messages:
    14
    Likes Received:
    0

    Managed to sort it this evening, I changed the external l IP for 3cx so it was the same as my gateway address and the forwarded traffic on the following port to my internal 3CX server.

    TCP/UDP port 5000
    TCP/UDP port 5001
    TCP/UDP port 5060
    TCP/UDP port 5090
    UDP ports 9000 - 9500

    Is there any reason why I shouldn't leave it like this? Or should I setup as per point 5 and use SNAT?

    Also, I take it I am fine allowing any external address to forward traffic on those ports - so the software app works correctly or do I need to add any additional rules.

    Sorry for the newbie type questions - I've only changed firewall settings for web server on ports 80/443.

    Thanks
     
  4. Mark Drabble

    Joined:
    Nov 13, 2017
    Messages:
    14
    Likes Received:
    0
    Setup SNAT with the external x.x.x.85 and this is now working.

    Just need to fine tune the ports for the mobile app.
     
Thread Status:
Not open for further replies.