Sonicwall config for successful firewall test

Status
Not open for further replies.

Alphabetic

3CX MVP
Silver Partner
Advanced Certified
Joined
Jul 1, 2016
Messages
6,558
Reaction score
2,571
1715710969964.png
1715710987955.png


3cxLANServices is made up of the services (ports) required.
3CXLAN Private is the LAN IP of the 3CX.
Ensure to turn off port remapping on 2 of the 3 NAT rules.
X1 IP is our WAN IP.
 
  • Like
Reactions: DesertGator
Hello.

I found that when following those instructions I was getting port remapping issues. Also, the GUI is outdated and that article could do with a refresh.
 
Hi there.
This guide is just an example and an idea on how this should be done.
If you are not sure, the best will be reaching the support team of your firewall vendor.
 
Hi Oleg. I think 3CX's Sonicwall guide needs updating otherwise there's no point it being there.
 
  • Like
Reactions: NCIA
Thank you for the feedback, however in our case as mentioned, is just an example.
 
Hi Oleg,

that KB should clearly state that the document is an example and isnt guaranteed to have the 3CX firewall checker to pass then. I cant have been the only one chasing my tail going over that document
 
What would be the change to the rule if the 3CX is not on the LAN, but rather is in the cloud?
3CX in the cloud is behind the sonicwall firewall? If not, this doesn't apply/doesn't matter - only if the sonicwall sites before the 3CX server to the internet. If so, the 3CX server is in LAN to the Sonicwall
 
View attachment 41449
View attachment 41450


3cxLANServices is made up of the services (ports) required.
3CXLAN Private is the LAN IP of the 3CX.
Ensure to turn off port remapping on 2 of the 3 NAT rules.
X1 IP is our WAN IP.
Thank you very much for this post. As using these settings I was finally able to get a "firewall pass" using the sonicwall.
My next hurdle is setting a "loopback" or what ever terminology you want to use for the sonicwall. Basically want to log into the admin console using the FQDN or IP and not be greeted with the "red error message" at the top saying the connection is not safe. I have tried a lot of different configurations and "guides" to try and accomplish this, but nothing has worked for me. The 3CX server is behind the sonicwall and I have tried following the "loopback guide" from sonicwall, but this doesn't seem to help. I was wondering if you had any issues with logging into the admin console using the FQDN? Any help on what settings I need to be implementing into the sonicwall would greatly be appreciated or even some screenshots of how you are able to accomplish this. Thank you again for your help and contribution to the forum!!!
 
Thank you very much for this post. As using these settings I was finally able to get a "firewall pass" using the sonicwall.
My next hurdle is setting a "loopback" or what ever terminology you want to use for the sonicwall. Basically want to log into the admin console using the FQDN or IP and not be greeted with the "red error message" at the top saying the connection is not safe. I have tried a lot of different configurations and "guides" to try and accomplish this, but nothing has worked for me. The 3CX server is behind the sonicwall and I have tried following the "loopback guide" from sonicwall, but this doesn't seem to help. I was wondering if you had any issues with logging into the admin console using the FQDN? Any help on what settings I need to be implementing into the sonicwall would greatly be appreciated or even some screenshots of how you are able to accomplish this. Thank you again for your help and contribution to the forum!!!
Assuming when you ping the FQDN is resolves external IP?

you need to use split DNS on your network to resolve local IP.

https://www.3cx.com/docs/creating-fqdn-split-dns/

If not, use hairpin NAT.

https://www.sonicwall.com/support/k...sing-public-ips-loopback-nat/170505780814635/
 
Assuming when you ping the FQDN is resolves external IP?

you need to use split DNS on your network to resolve local IP.

https://www.3cx.com/docs/creating-fqdn-split-dns/

If not, use hairpin NAT.

https://www.sonicwall.com/support/k...sing-public-ips-loopback-nat/170505780814635/
No, when I ping the FQDN it resolves to one of our external IP's.

I have tried to configure "FQDN split DNS" and "loopback NAT" for the 3CX server/FQDN and have not got it to work correctly, so I assume I have not got something configured correctly. I have followed the "sonicwall" guides multiple times to try and get this configured, but no success. I really do appreciate all of he help and support from you guys. Any suggestions or possible screenshots from a "working sonicwall config" or "sonicwall walkthrough guide" would greatly help, just to double check that I am creating the correct rules and settings.
 
What is your DNS server?
 
NAT
1719935645608.png
Access Rule
1719936018963.png
Further into follow this:

 
NAT
View attachment 42312
Access Rule
View attachment 42313
Further into follow this:

I will try both of your recommendations to see which one will work for me. I will give an update on which was successful for this situation. Never know, they both may wind up working. Thanks again for the help, recommendation and guidance, I really appreciate it.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,951
Messages
589,886
Members
164,843
Latest member
sambannoura