Linux command of setup firewall

Status
Not open for further replies.

siulung

Free User
Joined
Jul 25, 2020
Messages
2
Reaction score
0
Dear All,

Try to install v16.0.619 on Debian-9.4-x86_64. My current VPS vendor doesn't support 3CX Debian ISO install. I can only install with the following instruction command:
https://www.3cx.com/docs/manual/installing-debian-linux-pbx/

After that, Finished to Run the firewall checker, ALL pass with green color response “done"
Review the firewall configuration of following link:
https://www.3cx.com/docs/manual/firewall-router-configuration/

In part of "Configure the Ports for your SIP Trunk / VoIP Provider" & "Configure the Ports for Remote 3CX Apps"

May i know the setup command of the Debian for the following part? i am beginner of linux :P
1 Configure the Ports for your SIP Trunk / VoIP Provider
- Port 5060 (inbound, UDP) for SIP communications.
- Port 9000-10999 (inbound, UDP) for RTP (Audio) communications

2. Configure the Ports for Remote 3CX Apps
- Port 5090 (inbound, UDP and TCP) for the 3CX tunnel.
- Port 443 or 5001 (inbound, TCP) HTTPS for Presence and Provisioning, or the custom HTTPS port you specified.
- Port 443 (outbound, TCP) for Google Android Push.
- Port 2195, 2196 (outbound, TCP) for Apple iOS Push.

Btw, is it necessary to Disable SIP ALG in my case of installation 3CX on Debian VPS?

i checked the current status firewall lists below:
----------------------------
root@xxxxxxxxx:~# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT udp -- anywhere sip.mcast.net
ACCEPT tcp -- anywhere anywhere multiport dports 5000,5001,sip,sip-tls,5090 tcp flags:FIN,SYN,RST,ACK/SYN ctstate NEW
ACCEPT udp -- anywhere anywhere multiport dports sip,5090

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
------------------------------

Thank you for advise :)
 
Hi,

I think no further action is required.
The correct ports are opened.
If you VPS is behind a router then SIP ALG must be disabled.
 
Hi,

I think no further action is required.
The correct ports are opened.
If you VPS is behind a router then SIP ALG must be disabled.

hi complex1, Thanks for your reply.
My VPS is directly open to public in data center.
May i know how to know Port 9000-10999 (inbound, UDP) for RTP (Audio) communications was open?
I no ideas. also, the results of " iptables -L" command, it doesn't show any information of Port 9000-10999? am i right?

Why i have this answer, its because my SIP trunking vendor suspects that my VPS could be a Natting / Firewall method in place that could be routing the requests incorrectly. Also requests me to check again if the below ports are open for RTP traffic: 8000 to 65000 UDP.

I am confused how to solve the problem of firewall issueo_O
 
Hi ,
if you passes green firewall checker in 3CX and are on direct public access then no port to open, rules have been already done during 3CX install.
is your sip provider a 3CX supported one? did you added trunk with 3CX template?
 
@siulung

The ports you are referring to are intended for the routers, if they are used.
Because your VPS is directly connected to the internet ( Public IP=Network IP ) then no hardware NATting/Firewall is inuse.
The IP address can be checked in 3CX Management Console - "Settings > Network" and you shall see they are the same.
If the Firewall Checker passes all Green then the Firewall is function correctly.

If you use a unsupported provider, please use the "Generic SIP Trunk" template to add/create a SIP trunk.
 
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,924
Members
164,852
Latest member
priya