v16 & Ubiquiti EdgeRouter - FW ports 10600..10998 full cone test failed (only)

Status
Not open for further replies.

amaestracci

Customer
Joined
Apr 10, 2019
Messages
4
Reaction score
0
Hi every body

my config is :
EdgeRouter X SFP v2.0.1
3CX 16.0.1581 hosted

when run Firewall Checker, all test (also ALG) are OK except range 10600-10998...
full cone test failed for each.

I don't understand because the port fowarding is explicit

10220
10222

as show in rules stats, rules are good.

any idea for me ?

thanks
 
Rumor has it that it's a bug in either 3CX or the hosted side of the firewall checker. As long as you aren't having audio issue I wouldn't worry about it.
 
hum great.
at the beginning my problem is that our outside phones in Direct SIP are well provisioning but they don't register :-/
 
I just had this happen to me at a remote site. After turning off the ALG on the Edgerouter - make sure to save and apply the config after and then a reboot of the Edgerouter it all started working again.
 
SIP ALG seemed to have not affected the previous firmwares on Ubiquiti Edgerouters. It appears to affect them now. Heres the command to disable it:

configure
set system conntrack modules sip disable
commit ; save
 
Hi every body

my config is :
EdgeRouter X SFP v2.0.1
3CX 16.0.1581 hosted

when run Firewall Checker, all test (also ALG) are OK except range 10600-10998...
full cone test failed for each.

I don't understand because the port fowarding is explicit

View attachment 10220
View attachment 10222

as show in rules stats, rules are good.

any idea for me ?

thanks
Having just re-read that. 3CX is hosted and this is your local firewall (where the SIP endpoints are) or this is the firewall in front of your hosted 3CX instance? You say outside phones but if 3CX is hosted then all phones are outside phones. Please clarify your configuration.
 
From your configuration screenshots it looks like that you have opened ports 9000-9398 and 10600-10999. Make sure that all ports (9000-10999) are open or you will experience one way audio calls.
 
Having just re-read that. 3CX is hosted and this is your local firewall (where the SIP endpoints are) or this is the firewall in front of your hosted 3CX instance? You say outside phones but if 3CX is hosted then all phones are outside phones. Please clarify your configuration.

sorry.
our 3cx 16.0.1581 is hosted On-Premise on Shuttle at our main office, behind an EdgeRouter X SFP v2.0.1
Latest firmware of 66.84.0.35 on all Yealink Phones
all ports (9000-10999) opened (screenshot was test to check stats rules)
SIP ALG disabled
Disallow use of extension outside the LAN is not checked for the outside extensions
router rebooted

so first : yealink T46S/T42S outside, in a second office, phones connected in Direct SIP are well provisioning but they don't register.
also in the second office, we've a DECT W52P with 2 handsets/extensions which it is full operationnal.

and, second Firewall Checker failed on range 10600-10998
 
Last edited:
If you have more than one remote extension at a site I'd suggest making your life easy and your setup more firewall friendly by using a SBC. Do you see the registration attempts hitting 3CX for the remote phones and have you confirmed the remote location isn't blacklisted, or even better, white list it.
 
thanks, i'll work on this
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,920
Messages
589,744
Members
164,794
Latest member
avmullins