Please note that 3CX can utilize 5060 TCP and UDP, especially if you have remote phones, and some trunk providers....
Thanks for this BrettG
I've put it back.
As for having to reboot the box to get it back online, i think that is entirely something wrong with the OS itself not kicking the services back up properly, on our ISO installed systems we never have this issue.
This only started recently. Worked fine than did all the changes as per blog and suddenly it started to play up. TBH I have not left it for a time to see if it self restores, only about 10 minutes or so. Note it also works fine if I restart or stop and start the services via the console, only the FW check fails.
########################################################
Sure. As per the pic what I'm doing is:
- Allowing port 5060 from VoipDiscount (they actually have a range of possible IP's - hence the subnet)
- Allow port 5060 from Localphone (they only use a single IP)
- Block all other traffic trying to hit port 5060 (there's a surprising amount in the Draytek log file!)
- Allow port 5001 traffic from the EE network so the 3CX Android app presence works correctly. Quite a big IP range for obvious reasons.
- Block all other 5001 traffic
- Is a Draytek default rule
View attachment 10437
Thanks Cjay
That's interesting. It's got my head buzzing. :-D In a good way.
Would be interested to see how the rule itself is built. Feel free to PM me the details.
I use VoiP Discount and VoIP Talk too. So I guess they'd be in the same rule. You've blanked out the IP addresses, is that because they are specific to your account and not public?
The local phones and devices, all have their own allocated IP address on my LAN or assigned.
5001 rules. Bit uncertain about that one. Surely the rule(s) is allowing all on EE access, but cutting out those on other networks, and if you have more than one, then it doesn't actually save a great deal????
Sorry, these might be stupid queries and questions.