Looking for router screen shots of 3CX behind SonicWALL GEN7 that works

Status
Not open for further replies.

[email protected]

Customer
Joined
Mar 26, 2015
Messages
5
Reaction score
2
Every few years I try to get SonicWALL to successfully pass the 3CX firewall checker and have never had any luck.

Instead of using my several thousand dollar SonicWALL I use a couple of hundred dollar Ubiquiti.

If you have successfully passed the firewall checker with a SonicWALL GEN7 could you please post screen shots of the NAT, Policy Access Rule, VOIP Enable consistent NAT (disable SIP transformations) plus any other that are appropriate?

I have followed the instructions, adjusted for GEN7, to setup SonicWALL supplied by 3CX. Consistent NAT is enabled and SIP transformations are disabled.

A lot of advice is present on the forum, but I wanted to take the approach of actual info from a successful implementation.

Thank you!
 
Every few years I try to get SonicWALL to successfully pass the 3CX firewall checker and have never had any luck.

Instead of using my several thousand dollar SonicWALL I use a couple of hundred dollar Ubiquiti.

If you have successfully passed the firewall checker with a SonicWALL GEN7 could you please post screen shots of the NAT, Policy Access Rule, VOIP Enable consistent NAT (disable SIP transformations) plus any other that are appropriate?

I have followed the instructions, adjusted for GEN7, to setup SonicWALL supplied by 3CX. Consistent NAT is enabled and SIP transformations are disabled.

A lot of advice is present on the forum, but I wanted to take the approach of actual info from a successful implementation.

Thank you!

Also a SonicWall user. Does it matter that you pass the firewall test? We never have, but are functionally 100%. I never put too much stock into the thing as it's a fairly useless metric to confirm everything is working.
 
  • Like
Reactions: mcsphones
Yes, it matters that the firewall tester passes.

My perspective is that the firewall checker provides a solid base of confidence that a majority of what 3CX needs to correctly operate is fully operational. I will be the first to say that normally once you configure your network to support 3CX it seldom needs revisiting. However, after installing a new release, performing network software upgrades, or after upgrading hardware running the checker plus placing a few phones calls provides a lot of confidence things-are working-and will work-correctly.

It has been a lot of hassle over the years to setup a small separate network alongside of SonicWALL primarily for 3CX. But, the few times an issue arose, diagnosing was straightforward from a solid base.
 
  • Like
Reactions: N_G
Where does the FW test fail?
 
Also a SonicWall user. Does it matter that you pass the firewall test? We never have, but are functionally 100%. I never put too much stock into the thing as it's a fairly useless metric to confirm everything is working.
Us too; they are by far our largest firewall install base, and have lots of 3CX behind them. They never pass the firewall test, but work fine once configured properly. Gen5 thru Gen7 SW firewall devices in use.
 
r.dasilva
your screenshot looks "strange". I've installed 3CX on-prem behind an SMB Firewall ZyXEL USG and also behind an SophosXG successfuly. I'm useing one to many (outbound) and many to one (inbound NAT) rules.Never had a SonicWall in operation.

Perhapse it will help you to check you service objects on the SonicWall and the Port range for inbound and outbound serviecs. these are implemented in my case.

Media Outbound (direct media)
1702924042690.png

Media Inbound
1702924193405.png

STUN Outbound
1702924451081.png
SIP, Media and STUN had to be forwarded to the WAN as shown in total.


STUN Inbound
1702924353588.png
STUN Inbound-> STUN Ports to Media ports on 3CX.


3CX TUNNEL Outbound
1702924751083.png


3CX REMOTE Outbound
1702924904040.png

Only TCP required


3CX TUNNEL Inbound
1702925025026.png


3CX REMOTE Inbound
1702924963088.png

Hope this will help you to fix your errors as shown above.

Good luck
Chris
 
  • Like
Reactions: jed
@jed
Now I have forgotten to report a trap:
If i create an inbound rule on SophosG, the rule has an reflective rule included. this can make trouble, depending by the 3cx rule setup on an firewall.

Regards
Chris
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet