Hi
@JST I hope I am not intruding or "trying to teach my Granny....." as it were. There are many better guys than me out there. Also if I am coming late to the party I have been away for a while.
A few things, or helpful thoughts from my experience.
Firstly I have found that most problems are never with the 3CX, either Windows or Linux based.
I am also pretty sure your SIP provider has tested their platform to death and has overcome any issues as they have arisen from their multitude of clients.
So that probably brings us back to the Router/Firewall.
I know absolutely nothing about the Sophos but where I have had this problem I have upped the UDP portmap timeout.
So in your case: cat /proc/sys/net/ipv4/netfilter/ip_conntrack_udp_timeout 30
I would increase this. You could certainly make this 180 i.e. 3 minutes and even more without any major worries.
Actually if you look at your Sophos TCP timeout I am sure it'll be much bigger.
Wireshark etc.
The inbuilt capture feature of 3CX is good.
From the console go to "Activity Log" then "Settings" and switch to "Verbose". Click OK.
Click "Capture" and let this run for as short or long as your hardware will stand but especially if your fault is apparent at the time.
Once you think you have the information you need click "Stop" and you will then be presented with a choice.
If this is for your own purposes click "Your capture can be downloaded from
here".
The file downloaded can be opened in Wireshark.
If the guys at 3CX want the trace click "
Generate support information package" which will be emailed to you and you forward to them.
Remember to go back and set logging level to Low or whatever you prefer.
Finally if you are more familiar with Wireshark on your Windows laptop/desktop/server whatever then you might consider getting an inexpensive "Smart" switch which will do "port mirroring".
So you connect your router to the "mirrored" port and your laptop to the "mirror" port.
Preferably on a temporary basis - you can watch and log all of your network traffic via this mirror port. Obviously this can slow things down a bit etc. etc.
But even better in my experience get an old "HUB" which broadcasts all information to all ports.
I use an old D-Link DFE-908Dx.
I really hope this helps but especially that I don't offend.
John