Please help - I´m ended with my knowledge... | Mapping does not match. Mapping is....

mighty82

Customer
Joined
Nov 3, 2024
Messages
2
Reaction score
0
Hey hello together,
I´m from Germany and choose to write it here directly into the internation forum.
I have some problems/issues (Firewall-Related, I guess) where maybe someone from the international area can help/support me because I´m close to the end with my knowledge to be honest,.

Just a quick overview about my landscape:
Location B:
  • Linux Debian Hyper-V VM with on-prem 3cx installed
  • 172.16.52.11 3cx Server local LAN IP Address (static)
  • The firewall is Cisco Meraki MX85
  • Firewall Port forwarding as described I have implemented (LINK - done with step #1)
See below the current Firewall setting from Location B - I change the 443 and https in other ports 11443 and 11800:
Meraki_Port_forwarding_overview.png

Side note - If important:
There is a side 2 side VPN between two locations and in Location A there is another 3cx on-prem server (LAN IP 10.10.1.100)
This Location A 3cx server (10.10.1.100) will replace with the above mention new 3cx in Location B (172.16.52.11/22) 3cx Server


Now if I run the test, I see below output:
Firewall-Test_result.png

On 3cx Server in Location B all 3cx Services are up and running. I don't know where I should further search...
I checked this article, too, but to be honest and frank, I did not understand whether I should take action here. :confused:

So it would be cool If I got here some helping hands...

Big thanks
 
First of all I would like to point out that port 11800 being your HTTP port should not be forwarded from outside, and port 5061 does not require UDP.

Does this firewall service both locations and both servers? This might explain why the mapping does not match as the firewall might be servicing both servers.

When the mapping doesnt match a specific port number, it would mean that the firewall is not keeping the source port number the same, and is modifying it.
 
  • Like
Reactions: PaulC_
First of all I would like to point out that port 11800 being your HTTP port should not be forwarded from outside, and port 5061 does not require UDP.
Yah - Thanks, will delete it once everything is working.

Does this firewall service both locations and both servers? This might explain why the mapping does not match as the firewall might be servicing both servers.
No, Location A has its own Meraki Firewall and Location B has its own Meraki Firewall.
The on-prem 3CX Server 172.16.52.11 is located in Location B.

I had a long session with Meraki support today, and they told me and guaranteed with some pieces of evidence, that the Meraki Firewall as well as Meraki Switches working as expected and forwarding it through the Firewall/Switch. It seems something on the Server or Application side it the issue....

I checked the VLAN Tagging, on the Debian VM as well as Hyper-V.
I have added a static IP address on the on-prem 3CX Server and added the firewall rule without any restrictions from the VOIP VLAN to WAN...

I´m really confused and bit lost....
 

Forum statistics

Threads
111,956
Messages
589,927
Members
164,858
Latest member
MichaelRussell3