Sonicwall and 3CX

Status
Not open for further replies.

RCS Berger

Gold Partner
Joined
Aug 1, 2019
Messages
2
Reaction score
0
Hey

one newly customer uses a sonicwall TZ 300. Now we did a fresh install of 3CX (Debian, Hyper-V VM) and the Firewallchecker turns red, or even doesn't move at all. I checked the Sonicwall to be like in the manual https://www.3cx.com/docs/sonicwall-firewall-configuration/

If I change the Settings like Suggested in this Thread: https://www.3cx.com/community/threads/unable-to-pass-firewall-check-v15-with-sonicwall.48270/ , I get the error "Mapping does not match".

Firmware of the Firewall is 6.2.6.1-25n

Anyone can help me out with this?
 
We run ours behind a Sonicwall and all ok.

Looking on ours now, running v6.5....

On https://www.3cx.com/docs/sonicwall-firewall-configuration/ they say to disable SIP Transformations, but don't mention Enabling consistent NAT, we have it ticked, so maybe give that a go.

Otherwise, only other deviation I can see on our config is that we have a loopback entry in our NAT policies for our firewalled subnets, which i thing just keeps the internal traffic in.. been a while since I mucked around with them.
 
Hi

The firmware you are running is quite old. sw_tz-300__eng_6.2.6.1-25n was Release Date - Nov 02, 2016 ,
The current version is sw_tz-300_eng_6.5.4.4_6.5.4_44n

I would say that would be the first thing to look at.

We have a site that has about 30 phones behind a SonicWall with the phone provisioned using STUN.


Regards
Sergio Fernandez
 
Thanks for the Replies.

@eddv123 Thanks for the research, these are articles I already looked into. But after changing the existing rules to what is suggested in those threads, the SIP-trunks even failed to register anymore. After going back I still had the same error and I set up the rules via wizard again according to the 3CX documentation. Now the trunks register and calls are possible, but the firewall-checker still fails (full cone error) and I also can't access the PBX from outside LAN, nor register over the android app.
I'm not familiar with sonicwalls and playing around with the rules messed it up even more and I don't see why.

@ArtR I ticked the checkbox for consistent NAT, Still the same. We didn't Setup the Firewall so I gotta have a look for that kind of rule, not sure if that's what's missing.

@Sergio Fernandez The Support has expired so I won't be able to Upgrade. I'm sure it should be working with that firmware but I see this could be a problem.

@JohnS_3CX thanks, I think we got them covered.

I'll attach screenshots of my rules maybe this helps. (first two NAT rules are the old ones, which I just disabled at that point)
on NAT Rule #4 "Disable Source Port Remap" is ticked.
 

Attachments

  • NAT_Rules_3CX.JPG
    NAT_Rules_3CX.JPG
    49.2 KB · Views: 59
  • Service_Group_3CX.JPG
    Service_Group_3CX.JPG
    25.9 KB · Views: 52
  • Services_3CX.JPG
    Services_3CX.JPG
    40.2 KB · Views: 48
  • WAN-LAN_Firewall3CX.JPG
    WAN-LAN_Firewall3CX.JPG
    35 KB · Views: 52
Status
Not open for further replies.

Forum statistics

Threads
111,933
Messages
589,809
Members
164,808
Latest member
jsbjsb