Sophos XG - Firewall Test (Failing)

Status
Not open for further replies.

teagle

Customer
Intermediate Cert.
Joined
Jul 16, 2021
Messages
30
Reaction score
3
Hi All,

I wanted to put this to the community first before going to an actual support ticket.

1641500725144.png
1641500778351.png
1641500834003.png

It was also tested with a Any to Any rule which still failed.

1641500883485.png
Any ideas?

Thanks
Aaron
 
Assuming this is a Windows machine, did you make sure that these ports are open within the Windows Firewall or turn the firewall off completely for testing? Also make sure Public profile for Windows Firewall is NOT the active profile. Other than that. I myself don't have much at the moment.
 
By ticket you I assume you mean Sophos ticket because 3CX can't help with this.

Did you disable SIP ALG?
 
  • Like
Reactions: ChrisC_3CX
Just want to add that the "Mapping does not match" message usually means that port preservation is not being applied. I can't provide information for the specific firewall and it's configuration but you might want to look for settings like port remapping, port preservation or anything else that could potentially do some port remapping/translation and configure it accordingly.

Regarding SIP ALG there was a similar thread here that you might find useful: https://www.3cx.com/community/threads/sophos-xg-firewall.63433/

For more information on how the 3CX Firewall Checker works I'd recommend checking our documentation explaining it's internal workings: https://www.3cx.com/docs/firewall-checker/

Understanding how it works will surely prove useful for determining what settings/configuration might be preventing it from succeeding.
 
Things may have changed over the past 3 years, but we had a hell of a time getting 3cx to work correctly using a Sophos UTM (I realize you are using an XG) We ended up setting up a seperate Mikrotik router for use with our PBX Server. With Sophos we had dropped calls, audio issues, etc. Good luck!
 
  • Wow
Reactions: teagle
Have we just entered a world of pain?
 
Hi All,

I wanted to put this to the community first before going to an actual support ticket.

View attachment 26914
View attachment 26915
View attachment 26916

It was also tested with a Any to Any rule which still failed.

View attachment 26917
Any ideas?

Thanks
Aaron
We have a Windows 3CX behind a Sophos and the firewall is just fine. Have you by chance created a new Service Object with all the required UDP/TCP ports and edited the NAT policies that way?

It also might be SIP ALG. That has to be turned off from CLI. either SSH or Terminal from Sophos XG Web Admin. I perfer SSH.

CLI> system system_modules sip unload. A reboot of the firewall might be a good idea however not required.
 
  • Like
Reactions: ybello
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru