Passing the firewall test

Status
Not open for further replies.

Joe Schmitz

Free User
Joined
Feb 8, 2017
Messages
30
Reaction score
1
I have a question on how 3cx supports clients that do need to pass the firewall test.

The way we're running is there's a central office and 2 branch offices connected to the central office. As of now we have 3 digit dialing working between all 3 offices, as well as the 3cx PC client works without issues. We're not using the video conferencing, nor are we using the 3cx Android client to tie extensions to cell phones. So as of now we're working perfectly fine.

Upon running the firewall test we don't pass it 100%. We fail the 3cx SIP Server test because port 5060 "full cone test failed". 3CX Tunneling Proxy test failed because port 5090 failed the cone test. The 3CX Media Server failed because none of the hundreds of ports passed the full cone test.

My question is that in the state we're in right now, are we required to pass the firewall test even though we may not need certain ports open? We really do not want to open ports on the firewall if we do need them to. If we decide to leave them closed, are we still able to ask 3cx for technical support should anything go wrong?

Our biggest concern is having firewall ports open that don't need to be. If there's not a feature being used, then we'd prefer to not have it open.

Thank you
 
Last edited:
So it's common sense, or at least I think it is. If you ask someone for support regarding something that passes through the firewall, then yes they are going to tell you to make it pass the firewall test first. If it's something unrelated, then it shouldn't come up.

In your case, everything seems to be working so no real need to change anything. That being said, it may be a good exercise to make sure you CAN make it pass the firewall test so that doesn't become a hurdle at some point.
 
So it's common sense, or at least I think it is. If you ask someone for support regarding something that passes through the firewall, then yes they are going to tell you to make it pass the firewall test first. If it's something unrelated, then it shouldn't come up.

In your case, everything seems to be working so no real need to change anything. That being said, it may be a good exercise to make sure you CAN make it pass the firewall test so that doesn't become a hurdle at some point.

We can make it pass a firewall test, our main concern was network security. We absolutely do not want to open ports we do not have to.

Thanks for the answer.
 
Then you should be all set. Leave it be and if it comes up, you can open up the firewall to make them happy and then close it when all done.
 
We can make it pass a firewall test, our main concern was network security. We absolutely do not want to open ports we do not have to.

Thanks for the answer.
Currently we do the same thing, we open the ports up to the world for the firewall test. Once passed I lock down the SIP port to my sip provider.
 
The logical thing to do here would be to configure the ACLs on the firewall such that those ports are open only to the 2 branch offices and the sip provider. If your full cone support is failing, this is not due to closed ports, it is due to the lack of static NAT which can break down your SIP calls as well as cause audio issues.
 
Hello @Joe Schmitz

3CX support will ask you to pass the firewall checker if the issue is or could be related to the firewall. If you can pass the firewall checker if asked and replicate the issue then you should not have a problem.
 
Hello @Joe Schmitz

3CX support will ask you to pass the firewall checker if the issue is or could be related to the firewall. If you can pass the firewall checker if asked and replicate the issue then you should not have a problem.

Thank you Yiannis for the answer.

One thing I forgot to mention is that we have the 3cx servers communicating on a site-to-site VPN connection between the offices. Upon looking at the connection settings in the firewall, we are not filtering any ports between sites. This means in theory we are passing the firewall test if the ports were tested internally. I'm assuming when the firewall test must be coming from the outside, thus our firewall is blocking those ports.
 
You are correct, the firewall is checking the external connection and not internally.
 
Status
Not open for further replies.

Forum statistics

Threads
111,900
Messages
589,628
Members
164,765
Latest member
domi