- Joined
- Jul 1, 2016
- Messages
- 6,558
- Reaction score
- 2,571
What would be the change to the rule if the 3CX is not on the LAN, but rather is in the cloud?View attachment 41449
View attachment 41450
3cxLANServices is made up of the services (ports) required.
3CXLAN Private is the LAN IP of the 3CX.
Ensure to turn off port remapping on 2 of the 3 NAT rules.
X1 IP is our WAN IP.
3CX in the cloud is behind the sonicwall firewall? If not, this doesn't apply/doesn't matter - only if the sonicwall sites before the 3CX server to the internet. If so, the 3CX server is in LAN to the SonicwallWhat would be the change to the rule if the 3CX is not on the LAN, but rather is in the cloud?
Thank you very much for this post. As using these settings I was finally able to get a "firewall pass" using the sonicwall.View attachment 41449
View attachment 41450
3cxLANServices is made up of the services (ports) required.
3CXLAN Private is the LAN IP of the 3CX.
Ensure to turn off port remapping on 2 of the 3 NAT rules.
X1 IP is our WAN IP.
Assuming when you ping the FQDN is resolves external IP?Thank you very much for this post. As using these settings I was finally able to get a "firewall pass" using the sonicwall.
My next hurdle is setting a "loopback" or what ever terminology you want to use for the sonicwall. Basically want to log into the admin console using the FQDN or IP and not be greeted with the "red error message" at the top saying the connection is not safe. I have tried a lot of different configurations and "guides" to try and accomplish this, but nothing has worked for me. The 3CX server is behind the sonicwall and I have tried following the "loopback guide" from sonicwall, but this doesn't seem to help. I was wondering if you had any issues with logging into the admin console using the FQDN? Any help on what settings I need to be implementing into the sonicwall would greatly be appreciated or even some screenshots of how you are able to accomplish this. Thank you again for your help and contribution to the forum!!!
No, when I ping the FQDN it resolves to one of our external IP's.Assuming when you ping the FQDN is resolves external IP?
you need to use split DNS on your network to resolve local IP.
https://www.3cx.com/docs/creating-fqdn-split-dns/
If not, use hairpin NAT.
https://www.sonicwall.com/support/k...sing-public-ips-loopback-nat/170505780814635/
The sonicwall resolves from ISP and "Google" 8.8.8.8What is your DNS server?
I will try both of your recommendations to see which one will work for me. I will give an update on which was successful for this situation. Never know, they both may wind up working. Thanks again for the help, recommendation and guidance, I really appreciate it.
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.