Solved v16 to v18 Upgrade - Firewall Check reports SIP ALG fail.

Status
Not open for further replies.

StuNor

Customer
Joined
Mar 7, 2022
Messages
15
Reaction score
4
Hi,

I have just successfully upgraded 3CX from v16.0.8.9 to v18 build 450. The original v16 installation was from an official 3CX Linux ISO and I upgraded live from the system.

Post upgrade the SIP ALG check is failing. All other tests are passing. Generally the system is working normally and all services are running. All staff have been working normally and there hasn't been any issues with calls.

I have not changed the firewall rules and SIP inspection remains disabled so the test should pass. All tests were passing in v16. I have been monitoring the firewall logs and so far I have not identified any issues.

Has anyone else experienced this? May I ask for advice on what to check next.

Thank you for your help.
 
Try giving your router and PBX a reboot.
 
Hi @StuNor,

Just to add to @kieferschild's suggestion. The Firewall Checker hasn't changed between v16 and v18, so this may be something you noticed now. I'd suggest though investigating it as we do recommend that the Firewall Checker comes back all green.
 
Thanks guys. I agree, I do want all test to pass.

I have now rebooted 3CX and the firewall. Unfortunately, no change. The SIP ALG test is still failing.

I have one denied transmission on port 5060 from my PBX to 151.80.125.98 during the tests. A lookup of this address does not find a domain. How can I verify if this address belongs to 3CX and if I need to allow that transmission?

Cheers.
 
if destination is 5060, then it should be your SIP Provider Public IP , no?

I don't know if that helps but your IP is registred by RIPE NCC:

OrgName: RIPE Network Coordination Centre
OrgId: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL
RegDate:
Updated: 2013-07-29
Ref: https://rdap.arin.net/registry/entity/RIPE

ReferralServer: whois://whois.ripe.net
ResourceLink: https://apps.db.ripe.net/search/query.html

OrgAbuseHandle: ABUSE3850-ARIN
OrgAbuseName: Abuse Contact
OrgAbusePhone: +31205354444
OrgAbuseEmail: [email protected]
OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE3850-ARIN

OrgTechHandle: RNO29-ARIN
OrgTechName: RIPE NCC Operations
OrgTechPhone: +31 20 535 4444
OrgTechEmail: [email protected]
OrgTechRef: https://rdap.arin.net/registry/entity/RNO29-ARIN
 
No, definitely not our SIP provider. Thanks, my nslookup didn't get a host. I apologise for not performing a whois myself.

Not sure why the PBX is trying to contact this server. Thanks for confirming the communication is not coming from the firewall check.

I'll keep trying to identify the cause of the firewall check failure.
 
To be clear, I have added a screenshot of the test. All tests pass except SIP ALG.

SIP-ALG-failure.PNG
 
I have one denied transmission on port 5060 from my PBX to 151.80.125.98 during the tests. A lookup of this address does not find a domain. How can I verify if this address belongs to 3CX and if I need to allow that transmission?
I think I may know why your SIP ALG test is failing.
In order for a 3CX System to test SIP ALG, it communicates with a specific server: sip-alg-detector.3cx.com

Guess what IP this resolves to...

Find what is blocking access of your 3CX System to this IP and the test should succeed.
 
Thank you everyone.

I have added a new rule to the firewall to allow transmission to 151.80.125.98, UDP port 5060 and the SIP ALG test is passing.

I appreciate your help and advice.

As an aside, during the original commissioning of 3CX, I did find that UDP port 3478 also needed to be open for the firewall check to pass. I didn't find any documentation about that port at the time. It's not listed on this page, https://www.3cx.com/docs/ports/

I hope that info helps someone else.
 
Glad the issue is dealt with!

I'll go ahead and mark this as 'Solved'.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet