Port NAT issue

Status
Not open for further replies.

siva.manchala

Customer
Joined
Jan 4, 2022
Messages
3
Reaction score
0
We are using Fortigate Firewall (VM) and trying to configure the 3CX ports via firewall , but not working and error as below.

  • resolving 'stun-eu.3cx.com'... done
  • resolving 'stun2.3cx.com'... done
  • resolving 'stun3.3cx.com'... done
  • resolving 'sip-alg-detector.3cx.com'... done
  • testing 3CX SIP Server... failed (How to resolve?)
    • stopping service... done
    • detecting SIP ALG... not detected
    • testing port 5060... Mapping does not match 5060. Mapping is 1088. (How to resolve?)
    • starting service... done
  • testing 3CX Tunneling Proxy... failed (How to resolve?)
    • stopping service... done
    • testing port 5090... Mapping does not match 5090. Mapping is 1089. (How to resolve?)
    • starting service... done
  • testing 3CX Media Server... failed (How to resolve?)
    • stopping service... done
    • testing ports [9000..9398]... failed (How to resolve?)
      • testing port 9000... Mapping does not match 9000. Mapping is 1090. (How to resolve?)
      • testing port 9002... Mapping does not match 9002. Mapping is 1091. (How to resolve?)
      • testing port 9004... Mapping does not match 9004. Mapping is 1092. (How to resolve?)
      • testing port 9006... Mapping does not match 9006. Mapping is 1093. (How to resolve?)
      • testing port 9008... Mapping does not match 9008. Mapping is 1094. (How to resolve?)
      • testing port 9010... Mapping does not match 9010. Mapping is 1095. (How to resolve?)
      • testing port 9012... Mapping does not match 9012. Mapping is 1096. (How to resolve?)
 
Also, bear in mind that "Mapping does not match" may mean that port preservation is not being applied so look for features such as port remapping on the firewall and disable them. You may want to also take a look at our 3CX Firewall Checker documentation to better understand how the firewall checker works and hopefully use that information to determine what settings on your firewall you need to adjust to get the desired outcome.
 
To be completely honest, the guide may be outdated and is specific to the Fortigate 80C and to the Fortigate software available at the time the doc was published. That said, we cannot guarantee it will be sufficient for a different model or newer version but we do recommend at least taking a look as you may find that some options remain the same or are similar.
 
In more recent firmware versions for the FortiGate, there is a policy option labeled "Preserve source port" which can be enabled. It prevents NAT changing the port for outbound connections (as long as there are no conflicts with other active sessions). In the CLI, the config is "set fixedport enable" in the firewall policy.
 
Hi ,
I done but , same error while run the Firewall.

So please help me to resolve.

Regards,
Siva.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru