Solved Mapping issue w/ no firewall?

Status
Not open for further replies.

j-shep47

SMB User
Joined
May 16, 2022
Messages
7
Reaction score
1
Hi,

Quick rundown.
Had a 3CX system on test for my home office. Working great and loved it. This weekend I wanted to move it from my current environment [Windows 10 desktop system] to my server environment.

Backed up my working system no problem. Installed 3CX on my new Hyper-V server, installed no problems. After the install I gave it my backed up file from my desktop system. Went through fine, no issues, everything was great.
Looked to do a firewall check and I am now gettting "Mapping does not match 5060. Mapping is 1028"
I've spent hours looking and resolutions from this forum. None work, everyone goes on about port forwarding issues etc etc but makes no difference.

I thought to confirm any firewall issues with my router I put the server in a DMZ Zone to make it insecurely open to the world. This made no difference at all. So I also completely disabled the Windows built in firewall via Powershell and this also made absolutely no difference.

Can someone tell me what the hell is going on? If my server is behind absolutely no firewalls why am I still getting this issue? Is it something to do with the backup coming from another system perhaps?

Would really appreciate the help and I paid for the license just before I moved the system and now it's totally useless to me, annoyingly.

Tia
 
If you have SIP ALG enabled on your router, disable it.
What kind of router do you have?
 
Did you put it on the same IP or a different one? Could be a routing issue. Have you rebooted the router?
 
Usually most people have the ISP modem, and they also have their own router/firewall behind it.

You might do everything right on your firewall, but the ISP modem may still be messing things on the next hop before you hit the internet.

Also, even if you have read this article below, read it again and confirm every small detail is indeed the way we describe here:
https://www.3cx.com/docs/installing-microsoft-hyper-v/
 
Hi. Thanks for the replies.

IP address has been changed within the ISP router / modem to the new server which made no difference.

I have the modem acting as DHCP server. This is then linked to my 24 port managed switch.

I can't see it being a modem / firewall issue as the only thing that has changed is the machine it's now running on and obviously the IP address which has been updated in the firewall / modem settings.

Usually most people have the ISP modem, and they also have their own router/firewall behind it.

You might do everything right on your firewall, but the ISP modem may still be messing things on the next hop before you hit the internet.

Also, even if you have read this article below, read it again and confirm every small detail is indeed the way we describe here:
https://www.3cx.com/docs/installing-microsoft-hyper-v/

Thanks for the link as I've not seen this document regarding Hyper-V stuff! I'll go through that now and update today. Hopefully they'll be something in that document that will rectify the issue. I'll keep the post updated!

Thanks
 
If you see mapping does not match, it will be 100% the modem.

It's the only one which controls the NAT since you only have a switch after that.

If it's a managed switch, make sure that it does not run any services at all. Make it act like a dumb switch. Disable all helpers or anything with the word SIP in it.
 
If you see mapping does not match, it will be 100% the modem.

It's the only one which controls the NAT since you only have a switch after that.

If it's a managed switch, make sure that it does not run any services at all. Make it act like a dumb switch. Disable all helpers or anything with the word SIP in it.
Thanks for the response.

I get what you're saying, but surely if I've put the IP of the new machine in a DMZ zone whereby the modem will allow everything to and from that IP address with no firewall at all, why am I still getting the issue?

I can't see why just moving my system from one machine to another would cause the modem to suddenly have a firewall issue? Nothing has changed, both old and new machine are on the exact same network with the exact same network configuration. Make no sense to me.

I have also just gone through the guide you posted about Hyper-V configuration. Made no difference at all. Everything is set up exactly how the guide says.

Far as I'm aware there isn't much in the way of firewalls and so on with my switch. Please feel free to correct me on this but I can't see anything. Here is the model number "D-Link DGS-1210-28P"
 
I get what you're saying, but surely if I've put the IP of the new machine in a DMZ zone whereby the modem will allow everything to and from that IP address with no firewall at all, why am I still getting the issue?
DMZ is not as standard of a thing as you might think.. Each modem manufacturer may implement it differently behind the scenes, so there is not guarantee that DMZ mode will ensure success unfortunately.

You might also have some port-forwards in place that come in conflict with DMZ. I would recommend to factory reset the modem (with your ISP helping you of course) to ensure there is nothing left in memory.

Then manually open the correct ports and ranges, while ensuring that SIP ALG / SIP Helper / Or other ALG is 100% not activated.

Also, make 100% sure that the Windows firewall is turned off for all interfaces, and that you have not installed any antivirus or other software that would interfere.

Make sure that the Hyper-V machine has only a single NIC.

And finally, bypass the switch and hook up straight to the modem ports (they usually have 4 LAN ports).

This way you will be eliminating most of the common factors that could be causing remapping, even though I'm pretty confident it will be the modem's fault at the end of the day.
 
I'll give that a try shortly.

Can you give me a full list of all the ports that need forwarding to have a correctly configured firewall. I'm sure I've got them all set up anyhow, but I would like to make sure it's done correctly.

Thank you.
 
Sure thing: https://www.3cx.com/docs/ports/

You must forward all the ports that have a "Yes" in the required section.

The ones that are a range of ports, must also be forwarded as an entire range. Not just the individual first and last port.
 
Thanks for the link. Finally got this sorted! Bit annoying though.

So I've now done the following in order.

Re-done the port forwarding from scratch. Added all the ports listed in that document and the rage ones - Made no difference.
I found 2 settings in the modem "SIP ALG": Already disabled and "Conntrack SIP ALG": this was enabled, but I disabled it. This also made no difference.

I then completely disabled all firewalls on any network profile to rule that out, also made no difference.

I then rebooted the modem - also no difference. I then backed up the modem settings, done a factory reset and then reconfigured the modem again. Success! This seems to for now have solved the problem. No port errors on the firewall checker. I also re-enabled the Windows built in firewall and that seems to not be causing any issues either!

Thanks for the swifty support! Technology eh? Switch it off and on again and it sorts it. Would have thought in this day and again we wouldn't have to do stuff like this haha.
 
  • Like
Reactions: JohnS_3CX
Stuff gets stuck in the ACL tables sometimes, especially on consumer grade hardware ;)

A reset usually cleans them and you are back in business!
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet