Issues with incoming calls behind Sophos XG

Status
Not open for further replies.

ESMTULSA

New User
Joined
Nov 15, 2019
Messages
7
Reaction score
3
Hello,

I am having issues with incoming calls on 3CX behind a Sophos XG firewall. This previously ran behind a Pfsense firewall without issue, so I know it is a firewall problem. When I run the firewall check I get “full cone test failed” on the SIP port, tunnel port and media (9000+) ports. Outbound calls work fine. Tech support from Sophos tried several steps to diagnose and fix the issue without luck.

On the Sophos XG I have:

  • Disabled the SIP module
  • Modified the UDP timeout value to 150
  • Have forwarding rules for SIP, Tunnel, Management and Media ports.
  • Have a rule to allow the 3CX server access to WAN.

Any ideas what could be causing the issue?
 
I would try and ensure you have these ports allowed through in your Business Application Rule. Also make sure there isn't a rule above it that might be conflicting.

13967
 
All of those ports are forwarded and I have the rule listed at the top. Here is the DNAT rule.1397013971
 
I have everything set up just like that person. I believe the issue with the firewall wall check is that I was blocking all countries except the United States. I'm assuming the test tries to connect to the 3CX server with an IP outside of the the United States. Now I pass the firewall check but still have an issue with incoming calls.
 
You can try doing North America instead of using United States. I have a couple of XGs set up that way and the calls work fine.
 
That's what I'll do when I figure out the problem. Right now I have it set to any while I try to get it fixed.
 
Probably not what you want to hear but I have had a few setups with Sophos firewalls before and they are not the easiest firewalls to work with - Pfsense work without issue though I agree.

For on premise servers I have found the best way to configure 3CX is with a 1>1 NAT mapping rule/Full cone NAT where you forward everything from public to private: https://www.3cx.com/blog/voip-howto/static-port-mappings/

As posted above by @cobaltit Sophos also have a forum so you might want to look at that post or better yet post consecutively on there also.
 
Is Advanced threat protection enable on the XG? If so you need to exclude the 3CX box.
 
Is Advanced threat protection enable on the XG? If so you need to exclude the 3CX box.

I have Advanced Threat Protection enabled on our XGs and it doesn't interfere with the PBXs. I don't have the PBXs excluded in ATP either.


It sounds like it might be the country blocking in the Firewall Rule. I would just use the North American continent if you're concerned about having it set to ANY on the Allow Clients/Networks list in the DNAT rule.
 
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,817
Latest member
Innovative Advisory