pfSense 2.4.x full cone test failed

Status
Not open for further replies.

Jaymei

Bronze Partner
Intermediate Cert.
Joined
Dec 18, 2014
Messages
28
Reaction score
1
Hi Guys,

Been a while since I've been here and hoping someone can assist with this setup.
We have been running this for about 2 years now but with the recent events in the world we have all staff working from home.
This has presented us with an issue where the audio is missing from some calls on one side and delays with people hearing others.

The firewall checker has failed with the error above but the guide was followed to the letter (https://www.3cx.com/docs/pfsense-firewall/) in the most recent version of the software.
This has only been an issue in the past 3 weeks with nothing changed on the firewall or the 3CX setup so I am at a loss as to where the problems arose.
If anyone could point me in a direction that would be great :)
 
Do you have any packages running on it, like pfBlockerNG or IDS like Snort/Suricata?
 
We maintain over 250 pfsense firewalls, many with 3CX in use, post us or send me screenshots from your pfsense firewall on these two pages:
Firewall > NAT > Port Forward
and
Firewall > NAT > 1:1
and
Firewall > NAT > Outbound

I can likely have you all fixed up in a matter of a couple minutes. I have almost 15 years of pfsense experience.
 
Last edited:
  • Like
Reactions: Saqqara
Agree, with setting Outbound Nat to Hybrid.

I setup our first pfsense a couple of months ago, and was very straight forward to get it to work with 3CX.
 
So i have reviewed his pfsense config, he has a lot going on, and the rules he has for 3CX are far from ideal, they need to be simplified, and redone as he has protocols open that dont need to be in some places as well, and even some erroneous rules.

@Jaymei IF you are willing, i would be happy to do like a webconference, or shared screen or something and fix your pfsense 3cx rules, that will be easier than trying to give you change by change over the forums, as i think it will be easiest to just start fresh on the 3CX rules.
 
  • Like
Reactions: Evolute IT
Agree, with setting Outbound Nat to Hybrid.

I setup our first pfsense a couple of months ago, and was very straight forward to get it to work with 3CX.

He has grouped numerous rules togeather using port aliases such that he only has a single 3cx rule on the "port forward" page set to TCP/UDP, and setup conflicting 1-to-1 nat entries, and on all the screenshots the entire wan ip is censored such that its impossible to tell how many WAN IPs he even has in use, or which rules are using which ip....

Follow the 3CX pfSense Guide he claims.... But Follow the 3CX pfSense Guide, he did not... He might have kinda used it as a sort of reference, and then went his own direction completely.

Here is an updated Guide im actually writing for the 3CX folks, its accurate to the newest firmware's on pfsense, 2.4.4+
https://docs.google.com/document/d/1D_js8DrO0gDQalXgBXwIXcUuxXSEQwXAkg9Is1NPzD8/edit?usp=sharing
 
Excellent document on configuring pfsense for 3cx

do you setup traffic shaper for sip traffic ?
if you use traffic shaper, do you include any of the 3cx ports (I.e rtp ports), if you do how do you add these ports in the config.

i researched you run the wizard, which does ’prioritize voice over Ip traffic’ , but can see how you add other 3cx ports if these are actually required
 
Excellent document on configuring pfsense for 3cx

do you setup traffic shaper for sip traffic ?
if you use traffic shaper, do you include any of the 3cx ports (I.e rtp ports), if you do how do you add these ports in the config.

i researched you run the wizard, which does ’prioritize voice over Ip traffic’ , but can see how you add other 3cx ports if these are actually required

We dont usually need to implement QoS, as in our part of the world, big pipelines are the norm, thus QoS isnt required. Our slowest pipeline at a site is 25/5, while most of them are 50/10 or 100/20, or even faster.
 
i researched you run the wizard, which does ’prioritize voice over Ip traffic’ , but can see how you add other 3cx ports if these are actually required

pfSense's wizard will ask for an alias, which on our office router we set up to include our remote 3CX server (in our data center), or at the data center the alias has all SIP trunk providers and all 3CX servers we host. That wizard will prioritize traffic by adding a Floating (match) firewall rule for those IPs in the alias, for UDP traffic. If you want to limit to destination ports you can edit that Floating rule or copy the rule and edit as necessary.

There is probably a much longer answer about how to configure the traffic shaping. We've been using CBQ. There are many tutorials online about traffic shaping in pfSense including from Netgate.
 
Status
Not open for further replies.

Forum statistics

Threads
111,943
Messages
589,860
Members
164,832
Latest member
Boblatino