inhouse hosted 3cx and Meraki mx64

Status
Not open for further replies.
Is yours set NOT on the WAN port. Say my
WAN port is 209.168.183.20
I then NAT 209.168.183.21: (Required 3cxPorts) to Internal IP - Correct?

Is there any way I could take a look over teamviewer or something?
 
Is this how the test is meant to work, communicating with two different IP addresses and source port changing from a different external source address?
13274
 
whole bunch of extra requests are on the 10000 range compared to the 9000 range as well
13275
 
Is the 3cx Full Cone Nat test meant to respond from a different IP and Source port to what the Bind request has come from?
 
From Meraki

- capture "Traffic out to destination 54-39-182-217", LAN capture line#863 (time: 11:34:17.807734) > PBX 192.168.0.3 sending Binding Request to 54.39.182.217 via Source port 10664 and Destination port 3478. Internet capture line#111, MX passes through traffic to 54.39.182.217 with same Source and Destination port.

- capture "Traffic come from source 51.79.116.90", Internet capture line#280, IP 51.79.116.90 sends Binding Response to MX via Source port 3479 and Destination port 10664. LAN capture line#1021, MX passes through traffic to 192.168.0.3 with same Source and Destination port.

In MX point of view, it passes through traffic without changing any port numbers. In normal traffic flow, when client sending traffic to server, it expects the same server IP replies then MX is considering this is the same traffic flow and MX allows inbound (reply) traffic as MX is state-full firewall.

In this case, traffic sending to 54.39.182.217 but replies from 51.79.116.90. MX considers this is as different traffic flow and without Port-Forwarding rule, this inbound traffic will be dropped. But because you configure Port-Forwarding rule, then MX just passes traffic as second capture.

The questions now are;
  1. Why different server reply traffic Binding Response?
  2. As MX passes traffic through, does server see that traffic reaching the server?

Traffic out to destination (Our IP has been hidden)
13280

Traffic from remote destination for test (Our IP has been hidden)

13281
 
  • Like
Reactions: Evolute IT
@JohnS_3CX

From meraki:

I read the 3cx document and Port-Forwarding rule allows inbound traffic from different IP + port as expected then forwarding to MX LAN interface as it shows in the capture for port-10664. MX seems to be doing what it should do to allow traffic. Anyway, to understand and identify issue quicker, please contact 3cx support and conference call with Meraki. You can call in our support anytime when you have 3cx support on the call with you.
 
We use Meraki all the time with 3CX and no issues.

It should work when you are using:
Standard Port Forward (shares IP of MX)
1:1 NAT

It will not work when you are using:
1:Many NAT

Hope this helps.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,821
Members
164,813
Latest member
divdigital