Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

3cx full cone on XG 135

Guys i´m getting crazy.....

What i am doing wrong?

DNAT Rule done

SIP ALG deactivated

SNAT connected to the DNAT with MASQ

any ideas?



This thread was automatically locked due to age.
  • Hello Community,

    i'm right now also configuring a 3CX behind a ShophsXG 18 SFVH (SFOS 18.5.2 MR-2-Build380) and i got a SIP port error during the firewall check form 3CX.

    Configuration

    - Sophos XG is direct attached to a Modem and has the public IP at #Port1

    - 3CX is running the test except the test of the port 5060 (shown below in my graphic).

    IN/OUT bound rule or POrt 5060/UDP is configure

    IN/OUT for Media, STUN is working well.

    INBOUND calls are working.

    Here my Output with the one and only issue Port 5060. All other results are green and "done:

    Any SNAT/DNAT is based on the XG v18. No double NAT in place.

    Any Idea what's wrong with Port 5060 ?

    Regards
    Chris

  • Hi Chris,

    can you post a screenshot of your firewall and NAT Rules?

  • Hi Dvaid,

    thanks for you quick response. I was on the verge of despair, because I could not resolve the error.
    But after the twanzist Wireshark recording I saw it (ok sometimes you can not see the forest for the trees) and fices the port 5060 error as above shown.




    The Issue was in the INBOUND Rule #115 in my screenshot.

    I forgot the last entry to allow the revers route from STUN 3478-3479/udp to port 5060/udp at 3CX behind the XG.

    After i updated the enty.

    Now the 3CX is free of erros in the firewall check.

    Thanks again

    Regards

    Chris

  • Good to see you got it working!

    Sometimes going through everything we set up, results in locating errors.

    Something that caught my eye, in your S_SIP_IN you only have UDP and the 5060 according to the 3CX Ports list, also requires TCP. I did some more reading on the 3CX STUN-Server and it only uses UDP just like you have it set up... Am I going crazy or is something not right in the documentation scattered around the 3CX articles? Go figure..

  • I will create an internal configuration document to get not confused about the minimum requirements for IN/OUT Sevices (Protocol/Ports) to save time in the future Slight smile

    TCP is for TLS communication, but for the first step, the 3CX is running and in step two i had to check about Certifikate Update process without port 80/tcp in the inbound rule.

    Regards

    Chris

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?