3CX Advanced Concepts
The 3CX Advanced Concepts guide is designed for professionals that want to enhance their knowledge, skills and expertise in 3CX!
This guide will help you understand more advanced concepts related to the 3CX system, including network infrastructure, security, and more. It will give you the skills to confidently and effectively troubleshoot and resolve complex issues.
Take your 3CX knowledge to the next level!
Chapter 7: 3CX On-premise & Self-Hosting
With the 3CX on-premise and self-hosting solutions, you have complete control over your system; You’ll have the freedom to customize it to your specific needs, implement your security protocols, and hold full responsibility for its management and safety.
As you can understand, installing an on-premise or self-hosted 3CX solution requires additional technical knowledge. To set up and maintain the system, you'll need to know, amongst other things, server administration, networking, and VoIP technology.
This chapter will take you through the steps of installing and configuring the 3CX:
- On-premise: on your Windows or Linux machine.
- Self-host: on Google, Amazon, Azure or DigitalOcean Marketplaces.
For installations with up to 256 SC we strongly recommend 3CX Hosted, and for up to 10 users - 3CX SMB FREE, which are the most cost-effective and easy ways to host 3CX. 3CX Support does not cover OS / machine-related issues for self-hosted or on-premises installs.
Learning Material
- Install 3CX on Linux
- Installing 3CX on Windows
- Recommended Hardware Specifications for 3CX
- Deploy on:
Key Takeaways
In the seventh chapter of this guide we looked at how we go about self installing 3CX on both supported Operating Systems. Bare metal installs, on a local virtual machine or a cloud provider, you should be able to get the installation files and get your instances up and running in minutes.
Extra attention was given to the Hardware (physical or virtual) needed to run 3CX correctly. Take some time to note possible future growth as for some deployments upgrading the server might not be an easy task. Still later on we will see how that type of situation might be handled if it comes up.
Chapter 8: Firewall Configuration
A firewall is a network security system that monitors and controls incoming and outgoing network traffic, based on predetermined security rules.
On-premise and self-hosted installations require firewall configuration to allow system access from outside the network, i.e. remote extensions or web-based management. If the firewall is not configured correctly, it can prevent access to the 3CX system or leave it vulnerable to unauthorized access.
For this chapter, you need to be familiar with your firewall device and the routing. 3CX will not configure your firewall.
We’ll go through the main aspects of ports and routing as well as the Firewall checker feature. This includes understanding the necessary ports and protocols used by the system, configuring firewall rules to allow only necessary traffic, and detecting any unauthorized access.
Learning Material
- Firewall & Router configuration
- Why the Firewall Checker Does Not Lie
- Network Capture from Web Interface
Key Takeaways
With close attention to the information provided in this section you should now be able to set up your network correctly, permitting the correct operation of your 3CX PBX, whether on premises or in the cloud.
Pay attention to all the firewall and router settings needed, so that the right permissions are given and the facilities for secure operation via properly signed FQDNs are in place.
The firewall checker followed by the built-in Network Capture are tools provided within the 3CX PBX to help you troubleshoot and solve any networking problems.
Chapter 9: Backup & Restore
Backing up your 3CX system regularly helps prevent data loss due to hardware failure, software corruption, or human error. Backup and restore are also important when upgrading your 3CX system.
Let’s have a better understanding of what you must store, what the additional options are, where and how!
Learning Material
- Backup & Restore
- Supported FTP Servers for 3CX Backups - Windows
- Supported FTP Servers for 3CX Backups - Linux
- 3CX Backup & Restore Commands
- Call Recording Storage
Key Takeaways
Taking regular backups is a must to ensure your operational resilience in the event of technical failures or human error. 3CX provides facilities to take backups easily, on-demand or with a regular schedule.
An important part of a proper backup procedure is to have the backups stored in a different location than the server to be backed up. 3CX provides 3 such options within the Backup setup tab. We also took a look at the command line options for taking and restoring backups, which can be very valuable in certain circumstances.
Finally, we take a look at remote storage, a highly recommended step to ensure your PBX does not run out of disk space.
Chapter 10: Bridges
Do you want to connect two (2) 3CX systems? Worry not! Let’s say you have two offices in two different cities or even countries. How would you connect them to move back and forth? With a bridge, of course!
This chapter will explain how Bridges work and how to configure them. We’ll also have a look at different scenarios for better understanding.
Learning Material
Key Takeaways
Interconnecting disparate branch offices, optimising PSTN connections with local SIP Providers all are possible utilising Bridges that help unify your internal operations, share resources and provide resilience to your telephony setup.
We also revisited the 3CX SBC (we touched on it in our Fundamentals), looking with a little bit more detail how the 3CX Tunnel architecture streamlines telephony connectivity in a secure and easy to deploy manner.
Chapter 11: Basic Troubleshooting
As a 3CXpert you need to be able to troubleshoot any issue arising within the PBX in no time. 3CX has a variety of tools and resources to help you through this process such as the event log, audit log, Wireshark and more.
Learning Material
- How to collect Logs for 3CX
- How to use the 3CX Log Viewer
- Wireshark as a Diagnostic Tool
- SIP and RTP overview
- Breakdown of a SIP INVITE message
Key Takeaways
Building on some of the information from previous chapters, we learned what tools are at our disposal, within the 3CX PBX, provided by 3CX or external, in order to troubleshoot more complex problems if they arise. 3CX provides detailed logs as well as the tool to analyse them, and Wireshark can be used to drill down into any network related issues, and beyond.
We took a look at the details and idiosyncrasies of the SIP and RTP protocols, and how they work together to provide VoIP telephony.
Looking at the SIP INVITE message in detail, the different headers and how they affect the establishment of connections and calls was explained.
Chapter 12: Advanced Deployments
3CX PBX comes with facilities for Advanced Deployments and integrations (PRO & AI editions, some features might only be available for larger SC options).
This chapter introduces some of these facilities.
Learning Material
Key Takeaways
No user has the same needs. The wide range of integrations and customisation features available on 3CX allow you to tune each deployment to the specific needs of each organization.
Covering smaller businesses, the hospitality sector and customer-centric deployments, 3CX provides the tools for a successful deployment in any scenario.
The Data Export tools and APIs allow you to automate how you manage your system, and how to track the key metrics that matter to each business individually.
CRMs and SSO options help you integrate the PBX with your existing environment, and the API allows you to automate many of the repetitive tasks associated with a complex deployment.
Chapter 13: Security & Anti-fraud
Security is a very important issue for any business of any size. 3CX has in-built security features including Anti-hacking, TLS certificates, SIP Authentication, and IP Blacklist.
This chapter of this guide should be the first in your mind when time comes to deploy a production system. Security first is a key principle to ensure uninterrupted operation of any system.
Learning Material
- VoIP Security
- PBX Security Tips
- 3CX IP Whitelist / Blacklist
- How to check and block “Anonymous” Callers
- 3CX PBX Security - Reset credentials / Passwords
- Don’t be that guy. - Blog Series
Key Takeaways
Starting from the more general areas of how to do SIP securely, and how to secure a PBX, we moved into some of the security and anti-fraud facilities that come with 3CX.
Taking advantage of the 3CX IP White and Black list facilities we can make sure only the right people have contact with our PBX. An automated Blacklist shared between all the 3CX customers that choose to opt-in to it helps to thwart global threads quickly.
Blocking Anonymous callers secures your system from attacks and your users from fraud.
Finally we looked at how we can control access via a proper password policy, an IP based access control policy, and how to integrate 3CX with our company’s SSO providers and went through our “Don’t be that guy” blog series with key advice on keeping your system secure.
Chapter 14: AI Features
With the rise of AI in business, the 3CX PBX comes with built in AI features and tools, allowing you to leverage the latest technologies.
This last chapter of this guide should be the first in your mind when time comes to deploy a production system. Security first is a key principle to ensure uninterrupted operation of any system.
Learning Material
- AI Report Analysis
- Cloud Transcription
Key Takeaways
We end on the latest major additions to the 3CX PBX - AI powered intelligence and functionality. Using Grafana, amongst other tools, your PBX data can be directly visualised and integrated, allowing you to troubleshoot technical or operational issues quickly.
Transcription, powered by cutting edge AI models, Cloud based or On-Prem, lets you get to the core of the call directly, with AI generated summaries and sentiment scoring.
Finally we look again at the AI Agents, with a greater focus on the technology and backend configuration that gets them going.
Last Updated
This document was last updated 09 July 2026

