3CX for 11 sites

Status
Not open for further replies.

Cascada

Silver Partner
Basic Certified
Joined
Apr 30, 2019
Messages
37
Reaction score
18
Hi,
I'm trying to deploy 3cx for a customer with 11 sites (HQ + 10 satellites sites). I have read several threads about multi-site installation, but they are a few years old. I would like to know if anyone has experience with a deployment like this.

Environment: The 11 sites will be connected using 10 Mbps Ethernet (non MPLS). The HQ site will have aprox. 40 phones and each satellite site will have between 6-10 phones each. 48 SIP sessions in total. The customer requires site-to-site dial extension but it is minimal.
Options:
  1. A central 3CX PBX on the HQ running on a i3 server with 4 GB of RAM (Windows 10 Pro) + a failover server. SBCs on each satellite site running on a Windows 10 Pro with a Intel Celeron and 4 GB of RAM. Raspberry PIs could be an option for SBC, however I don't know how reliable they are.
  2. Individual 3CX PBXs (1 per site) running on Celeron + 4 GB of RAM and Windows 10 Pro.

Challenges with each option:
Option#1
  • A central PBX won't allow me to add failover POTS line in each site (mainly to cover 911 emergency calls, if the Internet goes down).
  • If the Internet goes down @ the HQ, everyone will be disconnected.

Option#2
  • Complex management (11 PBX to manage)
  • It must be a nightmare to bridge 11 PBX to create extension dialing between sites.
  • Each site will be limited to the number of specific SIP sessions assigned to it instead of using the pool of 48 SIP session available with option#1

Could you guys provide some opinions / suggestions about the "best" way to tackle this deployment?

Thanks in advance
 
Hi,
I'm trying to deploy 3cx for a customer with 11 sites (HQ + 10 satellites sites). I have read several threads about multi-site installation, but they are a few years old. I would like to know if anyone has experience with a deployment like this.

Environment: The 11 sites will be connected using 10 Mbps Ethernet (non MPLS). The HQ site will have aprox. 40 phones and each satellite site will have between 6-10 phones each. 48 SIP sessions in total. The customer requires site-to-site dial extension but it is minimal.
Options:
  1. A central 3CX PBX on the HQ running on a i3 server with 4 GB of RAM (Windows 10 Pro) + a failover server. SBCs on each satellite site running on a Windows 10 Pro with a Intel Celeron and 4 GB of RAM. Raspberry PIs could be an option for SBC, however I don't know how reliable they are.
  2. Individual 3CX PBXs (1 per site) running on Celeron + 4 GB of RAM and Windows 10 Pro.

Challenges with each option:
Option#1
  • A central PBX won't allow me to add failover POTS line in each site (mainly to cover 911 emergency calls, if the Internet goes down).
  • If the Internet goes down @ the HQ, everyone will be disconnected.

Option#2
  • Complex management (11 PBX to manage)
  • It must be a nightmare to bridge 11 PBX to create extension dialing between sites.
  • Each site will be limited to the number of specific SIP sessions assigned to it instead of using the pool of 48 SIP session available with option#1

Could you guys provide some opinions / suggestions about the "best" way to tackle this deployment?

Thanks in advance

Why not use a Cloud hosted central 3CX with 11 SBCs on each site?

This way, you avoid the need for POTS failover as the Internet is rarely down in the Cloud and it also allows for the mobile app and FQDN to work properly!

For the 911, you can simply configure the E911 based on caller ID directly in your provider (to allow address mapping) then if the power goes down at one site, they can use the mobile app with their extension in case of emergency.

Please note that SBCs will also get a big update in SP2 (probably late 2019) that will allow for easy remote management, so managing 11 SBCs become less of a PITA.

Honestly, the Option 2 is costly and a big headache to bridge them all then manage it.
 
  • Like
Reactions: craigreilly
An unexpected requirement came up. The customer is a small supermarket chain and they have PA systems at each location. I guess my only option will be local 3CX installations. I do not handle IT for this customer, so, I don't know if VPN is an option.
 
An unexpected requirement came up. The customer is a small supermarket chain and they have PA systems at each location. I guess my only option will be local 3CX installations. I do not handle IT for this customer, so, I don't know if VPN is an option.

In this case, here's my suggestion:

  • Quote a small VPN router (like Cisco SMB) and a PoE switch, at each sites.
  • Link each router to your Cloud PBX instance by VPN, with each site under its own subnet.
  • Use the router to create your own small subnetwork to their own, so you can manage it.
  • Since you are on VPN, every devices connected to the switch will connect to your 3CX via its private IP and thus passing through the VPN.

This way, you don't have to manage their IT and you install your own equipment on which you can configure QoS also, and you become independent of their IT.

Also, this fix the PA issue since all devices are "locally" routed via the VPN.
 
In this case, here's my suggestion:

  • Quote a small VPN router (like Cisco SMB) and a PoE switch, at each sites.
  • Link each router to your Cloud PBX instance by VPN, with each site under its own subnet.
  • Use the router to create your own small subnetwork to their own, so you can manage it.
  • Since you are on VPN, every devices connected to the switch will connect to your 3CX via its private IP and thus passing through the VPN.
This way, you don't have to manage their IT and you install your own equipment on which you can configure QoS also, and you become independent of their IT.

Also, this fix the PA issue since all devices are "locally" routed via the VPN.
A Snom PA1 is supported using an SBC. We use this for a few of our customers.
 
Wasn't aware. I'd still use a VPN for reliability.
A VPN is always better but when we have smaller sites or multi sites it can be cost prohibitive as many cloud suppliers charge per tunnel.
 
A VPN is always better but when we have smaller sites or multi sites it can be cost prohibitive as many cloud suppliers charge per tunnel.

I never said to use the provider's VPN.

I use StrongSwan to setup my IPSec tunnel and my Cisco router connects to it. It works perfectly and I am not charged by my provider (in my case, DigitalOcean).
 
  • Like
Reactions: Cascada
we have tons of snom pa1s out in service, as long as you go into the snom config, and change its local ports to ones that dont conflict with other phones, they work fine remotely, no idea why 3cx doesnt allow them to be provisioned this way within the system....

As for your VPN, get some pfsense firewalls, you can buy protectli devices on amazon and install it to them... We used to buy pfsense's own hardware, however after warantee issues, and then a growing failure rate of their hardware devices themselves, we switched to the protectli devices, and simply install their firmware to them. For small call license on-premise 3CX servers, the protectli devices also work quite well. Just dont buy the celeron models, j1800/j1900, etc. make sure its an atom quad core or i3 or i5 model, and your golden, there on amazon quite reasonably priced.

the Celeron models do not include any form of crypto acceleration and lag if you use vpns, the atom/i3/i5 models have AES-NI acceleration which makes a 75% difference in speed/function if VPNs are in use, and 50% even if VPNs arent in use because they are just better CPUs...
 
An unexpected requirement came up. The customer is a small supermarket chain and they have PA systems at each location. I guess my only option will be local 3CX installations. I do not handle IT for this customer, so, I don't know if VPN is an option.
You can deloy a SNOM PA1. They work in cloud environments
 
You can use also Mikrotik routers for VPNs. Smallest one (just US $20) -- HAP lite is perfect for remote sites. We have installed hundreds of them.

Speaking of NSA documented backdoor'd firewalls..... BTW, those have issues with throughput on decent broadband connections, and the firmware is not nearly as user friendly as others... Check the hardware specs on them, you get what you pay for....

Here, After a forum user notifies them of the bad news Mikrotik saves face and swears there is no problem even when presented with evidence...
https://forum.mikrotik.com/viewtopic.php?t=119255

Quoting Mikrotik Support from Post number 35
""...there is no way to access the device without asking the password from the administrator of the router.""


Here, they are proven to be lying:
  1. https://www.trendmicro.com/vinfo/us...routers-compromised-in-cryptojacking-campaign
  2. https://www.exploit-db.com/exploits/45578
  3. https://www.symantec.com/blogs/threat-intelligence/hacked-mikrotik-router
  4. https://www.hackread.com/mikrotik-router-vulnerability-hackers-bypass-firewall-malware/
  5. https://it.slashdot.org/story/18/09...orwarding-owners-traffic-to-unknown-attackers
  6. Even more Recent https://www.securitynewspaper.com/2...-routers-allow-hackers-to-deploy-dos-attacks/
End Rant
 
Last edited:
  • Sad
Reactions: complex1
You obviously didn't read all the info, the most recent vulnerability i mentioned, was a matter of a few weeks ago(#6), so no way it was "fixed" half a year ago ;) Also, to have so many 3CX installations and no partner status.... :confused:sketchy, we host literally thousands of lines..... And just recently went from Platinum to Titanium.

Anyway not here to argue, and there is a difference between someone pushing a certain product as the best, versus advising others to avoid a given product in favor of any other of their choosing due to a well documented history of security issues.
 
  • Like
Reactions: Evolute IT
I would like to add a small note as I see that VPN has been mentioned several times on this post.

We have several large sites (some as large as this one) where multiple VPN's are used (I prefer the VPN option over most).

What gets missed on the networking side is to configure multi-site VPN routing correctly, we use Drayteks mostly but each vendor has a different way of doing this: https://www.draytek.com/en/faq/faq-vpn/vpn.lan-to-lan/three-sided-communication-ipsec/
 
  • Like
Reactions: Evolute IT
Thank you all. Very good information. Nice to know SNOM PA1 works remotely. Good info about VPN routers.
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
111,924
Messages
589,754
Members
164,796
Latest member
Dame24