Hi all. Looking for some guidance. Been wrestling with this. External VoIP 3CX Softphone clients work fine with the 3CX tunnel method using port 5090. From both laptops and iPhones. Not tried a hardware Snom 320 with the tunnel yet. I'm sure that would be fine. However, I would like to test an external Snom 320 located at a satellite office using STUN. Despite having firewall rules forwarding ports 5060 TCP/UDP and port UDP 9000-9049 to the 3CX server local IP from the WAN I cannot get the Snom to register when located externally to the office. I see a STUN request issued from the 3CX server when the Snom attempts to register. Then nothing happens. So the Snom gets to the 3CX server to begin the STUN process. But then nothing happens. Also, the Firewall checker complains about port 5060 UDP and fails at Test2 "One to One port forwarding". Test 1 "reachability test" passes successfully. The internet traffic come into a DrayTek 2850Vn set to allow all ports from WAN to LAN with no filtering at all. A ZyWall USG 100 Firewall is connected inside the DrayTek to filter data from The Internet and pass it onto our LAN from there. My port 5060 traffic seems to work for the LAN and over our bridge to Ireland but not from The Internet. Is this a STUN / NAT config problem ? Is it the fact that the UDP packet doesn't "know" where to return to in test 2 ?