- Joined
- Nov 9, 2018
- Messages
- 5
- Reaction score
- 4
I've been reading various posts about this all morning and can not find anything that could be causing this. I've looked at all the common "culprits" on dozens of posts.
I can make extension to extension calls with no issues with clients that are on and off our internal network.
I can receive external calls from our SIP trunk with no issues.
External calls to our SIP trunk have one-way audio, the called party can not her me but I can hear them.
Here's some information...
On premise 3CX version 15.5.15502.6
One SIP trunk with SIP.US
PBX Delivers Audio is checked on the trunk
Firewall tests all pass
Firewall is Fortigate FG100D v6.0.3 build0200 (GA)
SIP ALG is disabled per this document:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD36405
Ports opened per:
https://www.3cx.com/docs/ports/
Did a packet capture on the DMZ from the firewall (before NAT), have 2500+ packets and I don't know where to start looking at them. Don't really want to post here as capture contains sensitive information.
Thinking a capture on the WAN port might also be helpfull to see what NAT is doing but don't know what kind of filter to apply to that capture. Without a filter there would be 10,000 packets in a few seconds.
One to one NAT between our external IP and the internal IP
The one-to-one nat for the PBX is on a different IP address than our main office NAT. We have a /29 address range with Comcast. The WAN interface is the first useable address in the /29 (.233) range, the 3CX net is the second (.234) and the default gateway is the last (.238)
Firewall is setup with a virtual IP and inbound rule for the one-to-one NAT inbound and a second firewall rule for the one-to-one NAT outbound. This is per this document:
https://forum.fortinet.com/tm.aspx?m=136309
Tried rebooting 3CX server, did not make any difference.
I see a lot of blocked traffic to the 3CX at the firewall, but it's all on various random ports that appear to be hackers probing:
RDP Deny: policy violation Implicit Deny
TCP/27019 Deny: policy violation Implicit Deny
TELNET Deny: policy violation Implicit Deny
TCP/4106 Deny: policy violation Implicit Deny
TCP/47675 Deny: policy violation Implicit Deny
TCP/31415 Deny: policy violation Implicit Deny
TCP/32169 Deny: policy violation Implicit Deny
TCP/53055 Deny: policy violation Implicit Deny
TCP/9265 Deny: policy violation Implicit Deny
TCP/5008 Deny: policy violation Implicit Deny
TCP/3007 Deny: policy violation Implicit Deny
TCP/4340 Deny: policy violation Implicit Deny
TCP/50138 Deny: policy violation Implicit Deny
SSH Deny: policy violation Implicit Deny
etc... etc... etc...
Any suggestions on what to look at next would be appreciated.
I can make extension to extension calls with no issues with clients that are on and off our internal network.
I can receive external calls from our SIP trunk with no issues.
External calls to our SIP trunk have one-way audio, the called party can not her me but I can hear them.
Here's some information...
On premise 3CX version 15.5.15502.6
One SIP trunk with SIP.US
PBX Delivers Audio is checked on the trunk
Firewall tests all pass
Firewall is Fortigate FG100D v6.0.3 build0200 (GA)
SIP ALG is disabled per this document:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD36405
Ports opened per:
https://www.3cx.com/docs/ports/
Did a packet capture on the DMZ from the firewall (before NAT), have 2500+ packets and I don't know where to start looking at them. Don't really want to post here as capture contains sensitive information.
Thinking a capture on the WAN port might also be helpfull to see what NAT is doing but don't know what kind of filter to apply to that capture. Without a filter there would be 10,000 packets in a few seconds.
One to one NAT between our external IP and the internal IP
The one-to-one nat for the PBX is on a different IP address than our main office NAT. We have a /29 address range with Comcast. The WAN interface is the first useable address in the /29 (.233) range, the 3CX net is the second (.234) and the default gateway is the last (.238)
Firewall is setup with a virtual IP and inbound rule for the one-to-one NAT inbound and a second firewall rule for the one-to-one NAT outbound. This is per this document:
https://forum.fortinet.com/tm.aspx?m=136309
Tried rebooting 3CX server, did not make any difference.
I see a lot of blocked traffic to the 3CX at the firewall, but it's all on various random ports that appear to be hackers probing:
RDP Deny: policy violation Implicit Deny
TCP/27019 Deny: policy violation Implicit Deny
TELNET Deny: policy violation Implicit Deny
TCP/4106 Deny: policy violation Implicit Deny
TCP/47675 Deny: policy violation Implicit Deny
TCP/31415 Deny: policy violation Implicit Deny
TCP/32169 Deny: policy violation Implicit Deny
TCP/53055 Deny: policy violation Implicit Deny
TCP/9265 Deny: policy violation Implicit Deny
TCP/5008 Deny: policy violation Implicit Deny
TCP/3007 Deny: policy violation Implicit Deny
TCP/4340 Deny: policy violation Implicit Deny
TCP/50138 Deny: policy violation Implicit Deny
SSH Deny: policy violation Implicit Deny
etc... etc... etc...
Any suggestions on what to look at next would be appreciated.