3CX Behind LAN versus DMZ w/SBC?

Status
Not open for further replies.

oguruma1218

Forum User
Joined
May 3, 2019
Messages
89
Reaction score
9
I'm kind of reticent to port forward ports directly behind my firewall into my LAN....

Is there any real downside to running 3CX in a DMZ (I would just give it its own NIC and entire network on my router) and then having an SBC behind the LAN?

Is that notably more secure?
 
I'm kind of reticent to port forward ports directly behind my firewall into my LAN....
Why? You port forward to the IP of the 3CX Server, rather than exposing all to the internet. You don't have to involve an SBC. This is how it is normally done on a local installation, with a few exceptions, of course.
 
If you port forward to a device behind your LAN, and that device becomes compromised (since it's exposed to the rest of the world), now you have a compromised device behind your LAN.

The same reason people put web servers and mail servers in a DMZ, no?
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,945
Messages
589,869
Members
164,836
Latest member
saranga