<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Port mapping for SIP services (3CX) in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102408#M4376</link>
    <description>&lt;P&gt;Did you disable SIP inspection per the following?&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120555&amp;amp;partition=Advanced&amp;amp;product=Small" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120555&amp;amp;partition=Advanced&amp;amp;product=Small&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Nov 2020 04:28:00 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-11-18T04:28:00Z</dc:date>
    <item>
      <title>Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102389#M4372</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm new to this checkpoint firewall. I worked on juniper networks and the settings there are pretty different to checkpoint. I have a 3cx phone system which uses port 5060 (TCP and UDP inbound) ,&amp;nbsp;&lt;SPAN&gt;Port 5090 (&lt;/SPAN&gt;&lt;SPAN&gt;inbound,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="c2"&gt;UDP and TCP) for the 3CX tunnel and&amp;nbsp;&lt;SPAN&gt;Port&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;9000-&lt;/SPAN&gt;&lt;SPAN&gt;10999&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(inbound, UDP) for RTP (Audio) communications and 5001 for inbound TCP.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Currently on the Checkpoint there are 4 subnets and the phone system is on one of them.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run a firewall checker from 3cx management console. The test results say that the port mapping from 5060 is incorrectly mapping to a different port. From my understanding here is that the source ports are not matching the destination ports. This happens for all the ports mentioned above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;So I'm taking it one issue at a time. Currently trying to troubleshoot one of the ports (Port 5060 TCP and UDP)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="c2"&gt;&lt;SPAN&gt;I'm having trouble create a NAT for the same.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class="c2"&gt;- Disabled SIP Alg on all SIP services.&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN class="c2"&gt;- Also on each of the sip services, I force the service to use the source port, which is the same&amp;nbsp; (eg. on the SIP_UDP service, in the advanced tab, I checked the option to use the source port and entered the 5060)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Things I have tried on the NAT&lt;/U&gt;&lt;/P&gt;&lt;P&gt;1. Translate traffic from the &lt;STRONG&gt;phone system&lt;/STRONG&gt; to any destination on &lt;STRONG&gt;SIP&lt;/STRONG&gt; ports as if the traffic is from the &lt;STRONG&gt;external IP (ours)&lt;/STRONG&gt; to the &lt;STRONG&gt;original destination&lt;/STRONG&gt; on the &lt;STRONG&gt;original service&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2. Translate traffic from any source to &lt;STRONG&gt;our external IP&lt;/STRONG&gt; on &lt;FONT color="#000000"&gt;&lt;STRONG&gt;SIP UDP Ports&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;as if the traffic is from &lt;STRONG&gt;Original source&lt;/STRONG&gt;&amp;nbsp;to the &lt;STRONG&gt;Phone System&lt;/STRONG&gt; on the &lt;STRONG&gt;original service&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;3. Translate traffic from any source to our &lt;STRONG&gt;external IP &lt;/STRONG&gt;on &lt;FONT color="#000000"&gt;&lt;STRONG&gt;SIP TCP&lt;/STRONG&gt; Ports&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;as if the traffic is from &lt;STRONG&gt;Original source&lt;/STRONG&gt;&amp;nbsp;to the &lt;STRONG&gt;Phone System&lt;/STRONG&gt; on the &lt;STRONG&gt;original service&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;On the firewall policy:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Outgoing - Allow outgoing traffic from the phone system to the internet on SIP tcp and SIP udp (using the SIP service group)&lt;/P&gt;&lt;P&gt;Incoming - Allow incoming traffic on SIP services to our external IP&lt;/P&gt;&lt;P&gt;I'm following the documentation provided by 3cx-&amp;nbsp;&lt;A href="https://www.3cx.com/docs/manual/firewall-router-configuration/" target="_blank"&gt;https://www.3cx.com/docs/manual/firewall-router-configuration/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any help here would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Andrew P&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 23:31:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102389#M4372</guid>
      <dc:creator>apatrick88</dc:creator>
      <dc:date>2020-11-17T23:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102401#M4373</link>
      <description>&lt;P&gt;You can't NAT SIP traffic without enabling deep inspection of SIP.&lt;/P&gt;
&lt;P&gt;Based on the tags in this message, I'm assuming this is a 1550 appliance, which is one of our SMB appliances.&lt;BR /&gt;Is this managed via the WebUI or is policy being pushed via external management?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 00:39:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102401#M4373</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-18T00:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102405#M4374</link>
      <description>&lt;P&gt;Hi Thanks for your prompt reply. The policy is managed using the webUI. As per 3cx, I disabled deep inspection of SIP..&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 00:53:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102405#M4374</guid>
      <dc:creator>apatrick88</dc:creator>
      <dc:date>2020-11-18T00:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102408#M4376</link>
      <description>&lt;P&gt;Did you disable SIP inspection per the following?&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120555&amp;amp;partition=Advanced&amp;amp;product=Small" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120555&amp;amp;partition=Advanced&amp;amp;product=Small&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 04:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102408#M4376</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-18T04:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102754#M4389</link>
      <description>&lt;P&gt;I have disabled Sip alg. that is the first thing we need to do. I configured the policy and the NAT. Now everything is working. Thanks for your help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically I needed to allow inbound traffic from the SIP provider to the firewall and then create specific NAT rules and use bare ports and then force the nat rule to translate as per the original packet. After the the phone system's firewall passed a full cone test.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 04:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/102754#M4389</guid>
      <dc:creator>apatrick88</dc:creator>
      <dc:date>2020-11-20T04:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/108043#M4673</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Could you pls share yr config. I got 3CX and 1450 Appliance and it literally turned me crazy. Probably general idea of yr settings would push me right way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks is advance&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2021 22:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/108043#M4673</guid>
      <dc:creator>obaghishvili</dc:creator>
      <dc:date>2021-01-17T22:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/109802#M4814</link>
      <description>&lt;P&gt;I have been trying everything on a VSX without success. 3CX works but Full Cone failed.&lt;/P&gt;&lt;P&gt;Can you please share a screenshot of your NAT config which is working&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 12:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/109802#M4814</guid>
      <dc:creator>Bavesh_MT</dc:creator>
      <dc:date>2021-02-04T12:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115090#M5054</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;has anybody a working configuration for the checkpoint and a 3cx PBX ?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 09:04:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115090#M5054</guid>
      <dc:creator>KistersSolu</dc:creator>
      <dc:date>2021-04-01T09:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115092#M5055</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;can anybody share a screenshot with a working NAT configuration for a 3cx PBX?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 09:12:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115092#M5055</guid>
      <dc:creator>KistersSolu</dc:creator>
      <dc:date>2021-04-01T09:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115093#M5056</link>
      <description>&lt;P&gt;Did you already look into&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk95369" target="_self"&gt;sk95369&lt;/A&gt;?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 10:44:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115093#M5056</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-04-01T10:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Port mapping for SIP services (3CX)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115094#M5057</link>
      <description>&lt;P&gt;These resolved my problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/3CX-Phone-System-behind-1450-Appliance/m-p/108280#M4708" target="_blank"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/3CX-Phone-System-behind-1450-Appliance/m-p/108280#M4708&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 10:46:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Port-mapping-for-SIP-services-3CX/m-p/115094#M5057</guid>
      <dc:creator>KistersSolu</dc:creator>
      <dc:date>2021-04-01T10:46:36Z</dc:date>
    </item>
  </channel>
</rss>

