Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT with Source Adresse Alias not working

    Scheduled Pinned Locked Moved NAT
    6 Posts 3 Posters 423 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      Lip
      last edited by

      Hi Guys,

      I'm trying to secure my 3cx PBX additionally. I would like to allow the SIP ports to enter only from an Source Address alias (tel.t-online.de).
      7c0e5bf8-a816-4900-8da0-54ef7cdf9224-image.png

      Here is a screenshot.

      b47e40a9-7307-42d1-a3b6-a3395b96a957-image.png

      If I delete the source alias, it works. It also works with the public IP address. But not with an alias.

      30a82f0c-884e-48e9-a547-277eb4b5fe38-image.png

      Does somebody has any idea?

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Check if pfSense can resolve the host name.

        1 Reply Last reply Reply Quote 0
        • L
          Lip
          last edited by

          4a013a9a-f22a-4bbd-812c-0b72617fe4a8-image.png

          It look's good!

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            And have you ensured that the inbound connections are deriving from that source IP only when the NAT source is any by checking the firewall log?

            1 Reply Last reply Reply Quote 0
            • S
              serbus
              last edited by

              Hello!

              Under Diagnostics -> Tables, what is in the TelekomSIP table?

              John

              Lex parsimoniae

              1 Reply Last reply Reply Quote 0
              • L
                Lip
                last edited by

                The problem is solved. The 3cx firewall check of course checks the ports from a different address than my aliases.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.