3CX failover configuration

Status
Not open for further replies.

mattik40

SMB User
Joined
Oct 24, 2018
Messages
2
Reaction score
0
hi,

Configuring a backup 3CX PBX for an active-passive fail-over setup. Currently we have 2 offices connected together by a vpn. In our office 1 there is our already working active PBX with an enterprise license, in the second office we are going to install our backup PBX in passive mode.
Actually in the first office we have all the phones provisioned as local(in-office) while in the second office there is an SBC to which all the phones are connected that routes all the voip traffic on the vpn via tunnel port. We're also using the 3CX provided FQDN (pbx.3cx.eu).
What I have done so far is setting up a zone for the pbx.3cx.eu on our internal dns servers following this article: https://www.3cx.com/docs/creating-fqdn-split-dns/ so that in our subnets it
resolves to the local ip of the pbx while on the internet to pbx’s natted ip. I then changed the interface to the FQDN rather than ip for all the phones in office 1 from the phone provisioning section.

Now I have three main doubts:

1)Having the local DNS servers resulting now athoritative for the zone pbx.3cx.eu will it cause problem with license activation or automatic external FQDN to ip association update on 3CX
servers when the fail-over occurs?


2)Is it possible to change the 3cxsbc.conf file on the SBC to point it to the FQDN? Because I've checked and it's pointing to the ip now.


3)When entering the license key will the second pbx recognize itself as being a passive and not start the sip related services?

Thanks for your input.
 
1. If you created the zone as pbx.3cx.eu then the only thing that is affected is that subdomain. If you created it as 3cx.eu the you could potentially have an issue but I doubt it. activation.3cx.com is one domain I know it talks to which won't be affected.

2. Possible yes, but I don't think that's the route you would go. Re-run the SBC setup and select yes for failover and you should be prompted for the secondary IP. Test, test, test

3. Follow the steps here and you should be good.

Couple of things to note/test:

- In your normal configuration you have the SBC and the 3CX on a different subnets. If you failover, the SBC and 3CX will be on the same subnet (assuming a flat topology or that your failover 3CX instance is going to be in that same voice subnet). I don't think this will be an issue since the SBC is not really routing but you'll find out in your testing.

- In my experience the SBC doesn't notice DNS changes. If you configure failover on the SBC you should be fine but if you don't and depend on DNS then test, test, test. You'd also want to test the failback scenario although that is manual IIRC so you can always restart the SBC in the same window when you failback.

Definitely update this thread with your results!
 
Thank you for your reply.

With the SBC not noticing the DNS changes do you mean that, in the case I modify the configuration file to point to the FQDN, at start up it’ll read the file, resolve the DNS, set some kind of variable and if a fail-over occurs the dns will change but the SBC will continue to point to the previous pbx’s ip and ignore the change in the DNS record?
Note that to update the internal dns name we are using a power shell script which runs on ours domain controllers that monitors the external FQDN. If it changes from the first ip of office 1 to the second ip of office 2 it assumes that a fail-over has occurred and modify the internal dns record.

Instead regarding the automatic update of the external FQDN the pbx directly contacts the 3cx’s servers for dns management, rigth? Do you know what their domain name is or it’s the same as activation.3cx.com?
 
Correct on the SBC. I move our internal instance around a lot as I test various cloud providers and I always have to restart the SBC for it to get the updated DNS (using a 3CX FQDN).

I don't know what other servers 3CX attempts to talk to but I doubt it's any of the domains assigned for PBX FQDNs so unless you are trying to lock down the firewall I wouldn't worry about it.
 
Status
Not open for further replies.

Forum statistics

Threads
111,914
Messages
589,709
Members
164,783
Latest member
GothamUser