UPDATE/EDIT: These changes didn't persist across a reboot! If anyone knows why 3CX seems to be overwriting/reverting firewall rules please let me know.

I am having limited success getting all the way through these directions but here is what I found on that from 3cx:
https://www.3cx.com/sip-phones/cisco-7940g-7960g/
I would NOT upgrade beyond 8.5.4 because they seem to indicate that's the last one they had tested/working.
I am currently at the step where I installed TFTPD-HPA on my linux 3cx distro and I cannot get the phone to communicate with the TFTP server because I don't know how to update the firewall on the server to allow communication to port 69.
I was able to update the firewall rules using some guidance from ChatGPT!
Pasted the interaction below:
To create a table using nft to allow incoming traffic from the IP range 192.168.1.0/24 to access port 69 on the localhost, you can use the following commands:
# Create a new table named "local_traffic"
sudo nft add table inet local_traffic
# Create a new chain named "input" in the "local_traffic" table
sudo nft add chain inet local_traffic input { type filter hook input priority 0\; }
# Allow incoming traffic from the IP range 192.168.1.0/24 to access port 69 on the localhost
sudo nft add rule inet local_traffic input ip saddr 192.168.1.0/24 tcp dport 69 accept
You can verify that the table has been created and the rule has been added by running the following command:
sudo nft list table inet local_traffic
This will create a new table named "local_traffic", a new chain named "input" in the "local_traffic" table and a rule that allows incoming traffic from the IP range 192.168.1.0/24 to access port 69 on the localhost.
Please keep in mind that this is just an example, it's important to customize the rules according to your needs and services. Also, it's important to test and verify that your services are still working properly after applying these rules.
Q:how can I restart the firewall to make that rule effective?
Once you have made changes to the nftables configuration, you need to reload the configuration in order for the changes to take effect. Here are a couple of ways to do that
(MY NOTE: Do 1 OR 2 OR 3)
- Reload the configuration using the nft command:
sudo nft -f /etc/nftables.conf
This command will reload the configuration file located at /etc/nftables.conf
- Restart the nftables service:
sudo systemctl restart nftables
This command will restart the nftables service and apply the new configuration.
- reboot the system.
sudo reboot
Please keep in mind that some distributions may use different paths or service names for the nftables configuration file or service, so you may need to adjust the commands accordingly.
It's important to test and verify that your services are still working properly after applying these changes, and also make sure that you have a backup copy of your firewall configuration before making any changes, in case something goes wrong or you need to revert to a previous configuration.