07/03/2567

การตั้งค่า SIP Server ทำงานร่วมกับ Firewall Fortigate

 ก่อนหน้านี้ เคยตั้งค่า Elastix ทำงานร่วมกับ Fortigate แต่ไม่สำเร็จ เลยใช้วิธีอื่น 

วันนี้พอดีเห็นมีการแนะนำการตั้งค่าเลยขอแชร์ไว้ครับ 


config firewall vip
    edit "VIP_wan-to-3cx"
        set extip "123.123.123.123"
        set mappedip "10.10.10.10"
        set extintf "any"
    next
end
config firewall ippool
    edit "IPPOOL_3cx"
        set startip 123.123.123.123
        set endip 123.123.123.123
    next
end
config firewall service custom
    edit "3CX HTTPS"
        set tcp-portrange 5001
    next
    edit "3CX HTTP"
        set tcp-portrange 5000
    next
    edit "3CX SIP"
        set helper disable
        set tcp-portrange 5061
        set udp-portrange 5060
    next
    edit "3CX STUN"
        set helper disable
        set tcp-portrange 5090
        set udp-portrange 5090
    next
    edit "3CX RTP"
        set helper disable
        set udp-portrange 9000-10999
    next
    edit "3CX WebRTC"
        set tcp-portrange 443
    next
    edit "3CX Server Test"
        set udp-portrange 3478
    next
    edit "3CX SMTP"
        set tcp-portrange 2528
    next
end
config firewall address
    edit "3cx-address"
        set subnet 10.10.10.10 255.255.255.255
    next
end
config firewall policy
    edit 0
        set srcintf "dmz"
        set dstintf "wan"
        set action accept
        set srcaddr "3cx-address"
        set dstaddr "all"
        set schedule "always"
        set service "3CX SIP" "3CX STUN" "3CX HTTP" "3CX HTTPS" "3CX RTP" "3CX WebRTC" "3CX Server Test" "3CX SMTP" "HTTP"
        set nat enable
        set fixedport enable
        set ippool enable
        set poolname "IPPOOL_3cx"
    next
    edit 0
        set srcintf "wan"
        set dstintf "dmz"
        set action accept
        set srcaddr "all"
        set dstaddr "VIP_wan-to-3cx"
        set schedule "always"
        set service "3CX STUN" "3CX WebRTC" "3CX HTTPS" "3CX RTP" "3CX SIP"
    next
end


https://blog.boll.ch/how-to-configure-the-fortigate-for-a-3cx-uc-system-with-sip-trunk/ 

ไม่มีความคิดเห็น:

แสดงความคิดเห็น