<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3cx behind Quantum Spark SMB (centrally managed) in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172419#M8294</link>
    <description>&lt;P&gt;Have you done also port/access/rules for your RTP traffic &lt;STRONG&gt;10400-10405 &lt;/STRONG&gt;for your phone&lt;STRONG&gt;s?&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2023 02:30:31 GMT</pubDate>
    <dc:creator>AndrewChui</dc:creator>
    <dc:date>2023-02-23T02:30:31Z</dc:date>
    <item>
      <title>3cx behind Quantum Spark SMB (centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172339#M8290</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I read several posts&lt;BR /&gt;I read several things&lt;/P&gt;&lt;P&gt;We have a cluster of 1600 firewall (R80.20.50) managed centrally (MGMT R81.10 Cloud)&lt;/P&gt;&lt;P&gt;We have:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Disabled Inspection on the protocol (5060-5061) by&amp;nbsp; Web page of Appliance&lt;/LI&gt;&lt;LI&gt;Disabled inspection on the protocol (5060-5061) of the object on the centralized console&lt;/LI&gt;&lt;LI&gt;With and without IPS&lt;/LI&gt;&lt;LI&gt;Create static rules for the incoming and outgoing for the NAT&amp;nbsp; (for 3cx server)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But the anomaly: the calls disconnect randomly&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone have some suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only one noticed is : that the source port of the Connection is changed from firewall chain, it is possible to disable this in the system?&lt;/P&gt;&lt;P&gt;Firewall Checker (tool on 3cx)&lt;/P&gt;&lt;P&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;resolving 'stun-eu.3cx.com'... done&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;resolving 'stun2.3cx.com'... done&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;resolving 'stun3.3cx.com'... done&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;resolving 'sip-alg-detector.3cx.com'... done&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing 3CX PhoneSystem 01 SIP Server... failed (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;stopping service... done&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;detecting SIP ALG... &lt;STRONG&gt;not detected&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing port 5060... &lt;STRONG&gt;Mapping does not match 5060. Mapping is 10400&lt;/STRONG&gt;. (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;starting service... done&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing 3CX PhoneSystem Media Server... failed (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;stopping service... done&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing port 5090... &lt;STRONG&gt;Mapping does not match 5090. Mapping is 10401.&lt;/STRONG&gt; (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing ports [9000..9398]... failed (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing port 9000... &lt;STRONG&gt;Mapping does not match 9000. Mapping is 10402&lt;/STRONG&gt;. (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing port 9002... &lt;STRONG&gt;Mapping does not match 9002. Mapping is 10403.&lt;/STRONG&gt; (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing port 9004... &lt;STRONG&gt;Mapping does not match 9004. Mapping is 10404&lt;/STRONG&gt;. (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing port 9006... &lt;STRONG&gt;Mapping does not match 9006. Mapping is 10405&lt;/STRONG&gt;. (How to resolve?)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="1 2 3 4 5 6 7"&gt;testing port 9008... &lt;STRONG&gt;Mapping does not match 9008. Mapping is 10406.&lt;/STRONG&gt; (How to resolve?)&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2023 13:22:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172339#M8290</guid>
      <dc:creator>lrossi89</dc:creator>
      <dc:date>2023-02-22T13:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: 3cx behind Quantum Spark SMB (centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172419#M8294</link>
      <description>&lt;P&gt;Have you done also port/access/rules for your RTP traffic &lt;STRONG&gt;10400-10405 &lt;/STRONG&gt;for your phone&lt;STRONG&gt;s?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 02:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172419#M8294</guid>
      <dc:creator>AndrewChui</dc:creator>
      <dc:date>2023-02-23T02:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: 3cx behind Quantum Spark SMB (centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172455#M8301</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, sure&lt;/P&gt;&lt;P&gt;FW RULE&lt;/P&gt;&lt;P&gt;in&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CatturaIN-1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19715iDF75DE4960ACBD15/image-size/large?v=v2&amp;amp;px=999" role="button" title="CatturaIN-1.PNG" alt="CatturaIN-1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;out&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CatturaIN-2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19716i46F7AD6A59657FBA/image-size/large?v=v2&amp;amp;px=999" role="button" title="CatturaIN-2.PNG" alt="CatturaIN-2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;static NAT&lt;/P&gt;&lt;P&gt;in &amp;amp; out&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CatturaNAT-1.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19714iA2C6FA5EF2DE9DCB/image-size/large?v=v2&amp;amp;px=999" role="button" title="CatturaNAT-1.PNG" alt="CatturaNAT-1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 09:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172455#M8301</guid>
      <dc:creator>lrossi89</dc:creator>
      <dc:date>2023-02-23T09:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: 3cx behind Quantum Spark SMB (centrally managed)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172617#M8306</link>
      <description>&lt;P&gt;Better contact TAC to get this resolved quickly !&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 09:09:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/3cx-behind-Quantum-Spark-SMB-centrally-managed/m-p/172617#M8306</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-24T09:09:01Z</dc:date>
    </item>
  </channel>
</rss>

