Trying to make 3CX work on a Unifi Dream Machine

Status
Not open for further replies.

ektarabel47

Forum User
Joined
Oct 20, 2020
Messages
2
Reaction score
0
As the title states, I'm trying to set up a 3CX PBX server on a Unifi Dream Machine in a corporate environment. The biggest issue I'm having right now is the port mapping. I'm currently using port forwarding to forward all necessary ports to the internal server and I've limited it to the IPs that our SIP provider uses, but 3CX requires Full Cone NAT. The issue with that is when I opened those ports to anyone I was getting attacked on those ports especially the main VOIP port. Any suggestions would be appreciated!
 
Hi,

It seems you already figured out how to configure your firewall for 3CX, and are just looking to increase your security. The only thing from above that you should take another look at is securing your full-cone natted SIP port to communicate only with your voip provider. From what you describe, the previous attempt appears to have not been successful if other random IPs can reach it.

That aside, the 3CX system protects you my blocking any unauthorized attempts by attackers. You can learn more about it here: https://www.3cx.com/docs/voip-security/

You can also learn how to better protect yourself by watching our pre recorded webinar linked here, where we go through a number of points of interest, some of which you may already be aware of:
https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/
 
Sometimes firewall needs you to create a block rule too. I know on Drayteks if you want to restrict to IP's you also need to create a block for that rule and set the allow rule higher in the order.
 
As the title states, I'm trying to set up a 3CX PBX server on a Unifi Dream Machine in a corporate environment. The biggest issue I'm havinTweakbox Appvalley https://vlc.onlg right now is the port mapping. I'm currently using port forwarding to forward all necessary ports to the internal server and I've limited it to the IPs that our SIP provider uses, but 3CX requires Full Cone NAT. The issue with that is when I opened those ports to anyone I was getting attacked on those ports especially the main VOIP port. Any suggestions would be appreciated!
issue got solved!!
 
We resell Unifi. Just making sure I understand by your title. When you say "trying to install ON a UDM", you meant you have a UDM on your network, and 3CX behind, right? You're not ssh'ing into the dream machine, and trying to install 3CX packages..?!
 
I've the same environment and have restricted the port forwarding to the IP of your trunk provider only to avoid any unsecurities. Yes, the firewall checker from 3CX shows a failure on the full-cone-nat. However, the system runs just perfect. Is there anything wrong with setting up the firewall like this?
 
Having FW red it's normal behavior if you set 5060 to only be allowed to provider public IP but no problem it works fine like that.
 
  • Like
Reactions: od-x
I've the same environment and have restricted the port forwarding to the IP of your trunk provider only to avoid any unsecurities. Yes, the firewall checker from 3CX shows a failure on the full-cone-nat. However, the system runs just perfect. Is there anything wrong with setting up the firewall like this?

The firewall checker is a tool, nothing more. If everything works, don't worry about the firewall checker. If you have an issue, then worry about it. But lets think logically about the firewall checker and what it does:

- Firewall checker listens for traffic on specific ports/IPs that 3CX needs to operate.
- You configured your firewall to block SIP traffic from everywhere but your trunk provider.

So if 3CX is not your trunk provider, what did you expect to happen?
 
I'm totally fine with this. That's what I'd expected when setting up the firewall like this. Just wanted to clear things up for the author of this thread and maybe anybody else looking for this.
 
Ahh ok, that makes sense. I was confused when I first saw this thread thinking the op was trying to install 3CX ON the UDM like the topic says, perhaps in a docker container or something rather than behind the UDM as it turns out.
 
I mean, yes! IF anybody manages to install 3CX literally ON the UDM I would be the first to try it out. But until then I'm happy running it in a Hyper-V machine. Took me also a moment to understand he installed the server in an "UDM controlled" infrastructure.
 
Status
Not open for further replies.

Forum statistics

Threads
111,993
Messages
590,175
Members
164,931
Latest member
admintest