Multiple 3CX Debian possible? pfSense router troubles

Status
Not open for further replies.

Peter Richardson

Customer
Basic Certified
Joined
Apr 6, 2017
Messages
286
Reaction score
16
Hi all,

I'm installing my second 3CX Debian and I am using pfSense for my router. Very simple network, one router, one switch, two 3CX machines.

The problem I have is that the firewall test keeps failing, stating that:
testing port 5062... failed
testing port 5062... unmatched mapping (59908)
testing port 5091... failed
testing port 5091... unmatched mapping (43685)
testing ports [9000..9255]... failed
testing port 9000... unmatched mapping (37861)
testing port 9001... unmatched mapping (25567)
etc etc

I have indeed forwarded port 5062 to the second 3CX machine, as well as 5091. So I'm not sure why this is happening. I'll post a screenshot of the firewall rules and NAT rules.

Another problem is that I need to change the ports used in 3CX from port 9000 - 9255 as these are already in use by the first 3CX machine, but I can't find the settings for this in 3CX.

Has anyone set up multiple 3CX Debian V15 within the same premises? Do you need multiple public IP addresses? Or is it possible to do it all with NAT?

Edit: I've just messed around with the firewall rules and managed to break the 1st 3CX machine too...now firewall test fails for this one too. Please help!!
 

Attachments

  • 2017-05-03 11_50_04-Photos.png
    2017-05-03 11_50_04-Photos.png
    86.6 KB · Views: 3
  • 2017-05-03 11_49_47-quarantine.launcestonit.com.au - Firewall_ NAT_ Port Forward.png
    2017-05-03 11_49_47-quarantine.launcestonit.com.au - Firewall_ NAT_ Port Forward.png
    74.1 KB · Views: 3
  • 2017-05-03 11_49_35-quarantine.launcestonit.com.au - Firewall_ NAT_ Outbound.png
    2017-05-03 11_49_35-quarantine.launcestonit.com.au - Firewall_ NAT_ Outbound.png
    78.1 KB · Views: 3
Last edited:
We are doing multiple 3CX on Debian behind pfSense, but we are using dedicated public IPs for each instance so we don't have to do NAT Magic. I suppose it can be done, but I'd rather not.
 
What sort of magic did you use to make it work with multiple IPs? Did you use virtual interfaces in pfSense? I have never had more than one static IP before, so this sounds terribly difficult!
 
And does anyone know how to modify the RTP ports? Usually 9000 to 9500, but how do I specify different ones for the second machine running 3CX?
 
So I have been trying every different possibility for ports, NAT, firewall, etc with pfSense...going on 5 hours now, and I think I'm ready to give up. I don't think that it is possible for 3CX to communicate on any port other than:

5060 (sip)
5061 (secure sip)
5090 (tunnel)
5001 (web interface)
443 (HTTPs / presence)
9000-9500 (rtp)

It seems that even if you are a NAT magician, it just WILL NOT work, probably something to do with the Debian firewall, or wrong port origination, agreed?
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,860
Messages
589,437
Members
164,700
Latest member
Apollo Cloud