3CX in DMZ: Port Forward vs SBC?

Status
Not open for further replies.

oguruma1218

Forum User
Joined
May 3, 2019
Messages
89
Reaction score
9
I've been running 3CX for a small home office for a while. I've been using a Raspberry Pi located behind my firewall. It works fine, but I want something a bit more robust and secure.

I'm going to install this on a KVM and place that machine in a DMZ.

I'm using PfSense as a Router. I have 3x Yealink phones and I use the softphones occassionally.

What's the best way to get the SIP traffic from the LAN to the DMZ interface?

The Raspberry Pi SBC doesn't seem like a bad way to go, since I won't have to punch holes from the LAN > DMZ. However, it creates another point of failure (the SBC itself).

Of course, I could just punch the holes from DMZ > LAN and forego the SBC, but I suppose that's theoretically less secure (or is it?).

Any input on this?
 
If you configure the pfsense per the guide provided here, you do not need to use a DMZ at all for security, it really wouldnt benefit you at all. Just put it on the LAN and be careful with the port forwards.
 
Status
Not open for further replies.

Forum statistics

Threads
111,943
Messages
589,861
Members
164,833
Latest member
Edal