Restricting Sonicwall Outbound Access Rule

Status
Not open for further replies.

chadsawyer

Free User
Joined
Feb 1, 2022
Messages
3
Reaction score
0
We have an audit finding that does not like our outbound 3CX sonicwall firewall rule allowing connections to ANY on ANY port. I tried restricting it to the 3CX services group, but that breaks external SIP trunks (no audio). Any idea how I can restrict this rule and keep the external SIP trunks operational?
 
What exactly, is the concern, with outbound connections?
 
It was an audit finding against us for having too broad firewall rules. Generally we have to define either a port group and/or a destination IP to satisfy them.
 
Thank you for the reply. I have read over those many times. The one specific to Sonicwall does not discuss an outbound access rule at all. I believe it is expecting a default allow rule at the end of outbound rules.
 
No the Sonicwall doesn't, because 3CX is not a security company and the focus is to provide guidance on what 3CX needs in order to function. It's up to you to mesh what 3CX provides with what your security requirements are. There's actually no outbound firewall rules mentioned at all in the Sonicwall guide, so technically this isn't even a 3CX issue, it's a firewall issue. And to that end, the first link lists the specific ports, protocols, direction and resources used and can be used to craft a more restrictive outbound policy..

The other option is to move your 3CX to the cloud, or at least out to a DMZ and then this becomes a non-issue.
 
  • Like
Reactions: NickD_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru