Solved Remote Stun behind Palo Alto

Status
Not open for further replies.

twisted1

Gold Partner
Joined
Feb 18, 2011
Messages
34
Reaction score
7
All,

A client of our hosted 3CX solution is configured for Remote Stun and has been golden for a year. This weekend they changed their Firewall from Sonicwall to Palo Alto. Now we are seeing the same extensions listed multiple times in the Phones list AND they cannot RECEIVE calls. They can make them just fine. If they connect from another network NOT behind the PA they are fine.

So, clearly it is the device.

That said, we don't manage it for them and are not privy to its configuration, nor do we know those devices so cannot help.

I have requested that they disable SIP ALG (SIP Fixup) which they claim to have done. I am not sure what else to suggest. Any PA guys out there with suggestions? I can't even use 3CX to test since the server is in MY network so the Firewall Test is useless.

Thanks!

Scott
 
You're going to need to poke a bunch of holes in the firewall for remote STUN to work.

Why not setup a 3CX SBC instead? That /should/ traverse the firewall without having to poke any holes in it, won't require any additional setup as long as SIP ALG is disabled, and will be much more stable.
 
Was never needed before as all was working swimmingly. Preferred not to use that method as we would then have an appliance in their network to maintain and we don't provide that service to them currently.

Is there something specific you can point me to that we need to have them open for Remote Stun in particular?
 
Was never needed before as all was working swimmingly. Preferred not to use that method as we would then have an appliance in their network to maintain and we don't provide that service to them currently.

Is there something specific you can point me to that we need to have them open for Remote Stun in particular?

Does each extension have a different SIP port and RTP port range defined in 3CX?
 
Turns out it was NOT a port issue which makes sense. I was confused since I had never opened ports in the FW on the STUN side before, only on the server side.

The FW Admin had adjusted the UDP Timeout values from their default of 1 hour to 5 seconds. So, every time the phone connected, the firewall would yank its established connection away from it. Once we changed that value back to the defaults, the duplication disappeared and calls worked in both directions.
 

Attachments

  • Palo Alto SIP Settings.PNG
    Palo Alto SIP Settings.PNG
    169.8 KB · Views: 122
Glad it's resolved. Have a great day.
 
Glad to see the issue has been resolved and thank you for updating the thread with your solution. I am sure many people will find this helpful.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,901
Messages
589,636
Members
164,768
Latest member
Eagle Man