Try Out the New 3CX SIP ALG - Firewall Check

Status
Not open for further replies.
Working now on OVH now too !!
 
  • Like
Reactions: N_G and StefanW
Please try again now and see if that works now. There was an issue with the servers services and it is now resolved

This fixed my issue. The firewall check is now passing. Thank you.
 
  • Like
Reactions: N_G and StefanW
working on Meraki MX80 now. Thanks
 
  • Like
Reactions: N_G and StefanW
If you are interested:
I can confirm that the Draytek 2710n, Draytek 2130n, MicroTik RB2011 and OVH pass the Firewall Check test.
 
  • Like
Reactions: StefanW and N_G
As seen by others, the AGL firewall test is now working correctly for me also. Thanks.

[ For reference, the firewall in use is pfSense (v2.2.4) ]
 
  • Like
Reactions: StefanW and N_G
Works with UniFi USG3. Detected ALG when it was on and passed when it was off.
 
  • Like
Reactions: N_G and StefanW
Just installed 3CX Debian, ran the firewall checker and saw the new SIP ALG detection had failed. I logged in to my router and disabled the SIP ALG and re-ran fw checker.. It passes. Glad you added this, I had no idea SIP ALG ws on by default on my router :)

Router: Cisco 881W
 
  • Like
Reactions: N_G and StefanW
Thank you all for your feedback. The more firewalls we test the better the service will be.
Keep it coming :)
 
  • Like
Reactions: StefanW
Zywall USG50 - Works. It will show the ALG failure when enabled and passes when turned off.
 
  • Like
Reactions: StefanW
I am just setting up a new Debian installation ver 15.5.5 with a mikrotik router.
      • resolving 'stun-au.3cx.com'... done
      • resolving 'stun2.3cx.com'... done
      • resolving 'stun3.3cx.com'... done
      • resolving 'sip-alg-detector.3cx.com'... done
      • testing 3CX SIP Server... failed (How to resolve?)
        • stopping service... done
        • detecting SIP ALG... failed (How to resolve?)
        • testing port 5060... not reachable (How to resolve?)
        • starting service... done
      • testing 3CX Tunneling Proxy... failed (How to resolve?)
        • stopping service... done
        • testing port 5090... not reachable (How to resolve?)
        • starting service... done
      • testing 3CX Media Server... failed (How to resolve?)

I'm certain the ports are open. When I try to use telnet on port 5060 from outside, it connects.
 
  • Like
Reactions: StefanW
@David Beveridge,

I'm using a Mikrotik also without issues.
Please go to IP > Firewall Service Ports and disconnect the SIP ALG service and try again.
 
  • Like
Reactions: StefanW
I've read both of those guides and I've disabled the sip alg service.
 
I read somewhere that the tests https://www.ssllabs.com/ssltest/analyze.html should return an A+ and I though I'd give it a go.
I found that the test only allows tests to port 443 and my PBX wasn't listening on that port. So I edited the nginx config file.
I added this line
listen 443 ssl;
above the same line for port 5001.
e.g.
root@pbx:~# vim /var/lib/3cxpbx/Bin/nginx/conf/nginx.conf
root@pbx:~# nginx -t
nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
nginx: configuration file /etc/nginx/nginx.conf test is successful
root@pbx:~# systemctl restart nginx

For some reason, the firewall test now works. Dunno why though.
 
3CX v15.5 on Windows 2008 R2 server, with cisco router 887VA and sip ALG on router disabled for tcp and udp on 5060 port, TEST ALL OK on firewall check!
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,832
Messages
589,286
Members
164,662
Latest member
DejanMDS