3CX License Question & SMS / 2FA Gateway

Status
Not open for further replies.

netvoip

Free User
Joined
Nov 30, 2020
Messages
11
Reaction score
0
Hello,

For a client I am looking to deploy for 3CX Pro or Enterprise, and need to understand how the user is defined.If we are using Bandwidth as SIP Trunk, and have 5 internal users those 5 users can be assigned more than 1 DID, is each DID considered a user or just the actual internal extension is defined as 1 user?

Also most importantly need the ability to do inbound / outbound Text messaging for customers & 2FA, is this supported by 3CX ? I cannot find that in the feature comparison list.

Thanks!
 
Each extension is as a "user".
3CX can have unlimited extensions, you're limited only by how many simultaneous calls your license is, and of course how many trunks you have with your SIP provider.
If you wanted a DID to come in to multiple users you would create an inbound rule to go to a group or extensions either via ring group or queue.

SMS is currently only available in the beta but wont be long before it's put in to production.

https://www.3cx.com/blog/releases/update-7-alpha/

2FA is also not native to 3CX but I imagine, in time, it will come. 3CX has a host of anti-breach measures which protect the system which includes locking down access via IP.

https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/
 
  • Like
Reactions: Evolute IT
Each extension is as a "user".
3CX can have unlimited extensions, you're limited only by how many simultaneous calls your license is, and of course how many trunks you have with your SIP provider.
If you wanted a DID to come in to multiple users you would create an inbound rule to go to a group or extensions either via ring group or queue.

SMS is currently only available in the beta but wont be long before it's put in to production.

https://www.3cx.com/blog/releases/update-7-alpha/

2FA is also not native to 3CX but I imagine, in time, it will come. 3CX has a host of anti-breach measures which protect the system which includes locking down access via IP.

https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/

Thanks very much @kieferschild, so what your saying is if my client has 5 internal extensions even if they have 15 DID's routing to each of those 5 (15x5 = 75 DIDs) the cost of licensing is only 5 as long as only 5 users are actively using (aka 5 extensions?).I understand that 3CX is unlimited extension and I am limited by the SIP trunk provider DID's and the license.Just wanted to get a hang of the costs per user per year.

I am aware of that inbound DID rule for routing a DID to a specific extension.

Also I thought SMS & 2FA is the same thing basically using Text messaging for 2FA..

I hope they get it out of Beta soon on the SMS feature, mainly need text + call support. So far the free version testing is yielding good results
 
You can have 1000 DIDs and 3000 extensions. As long as your 3cx license covers how many simultaneous calls you want at any one time you’ll be fine.

example:

8SC Pro

I can have 8 calls happening at once to any DID but cannot make or receive a 9th
 
  • Like
Reactions: Evolute IT
Also I thought SMS & 2FA is the same thing basically using Text messaging for 2FA..
If you plan on using 2FA via SMS, just don't use it. It's not secured at all. SMS are easy to hack/clone the SIM.

As for the SMS feature itself, it is beta but coming probably by the end of the month if their testing goes well. It's a big upgrade so it takes more time than a regular update.
 
If you plan on using 2FA via SMS, just don't use it. It's not secured at all. SMS are easy to hack/clone the SIM.

As for the SMS feature itself, it is beta but coming probably by the end of the month if their testing goes well. It's a big upgrade so it takes more time than a regular update.
Thank you for the suggestion.

But if our DID line is used for SMS, how can it be hacked? other than our epabx (3cx) server itself being hacked or a 3cx user account being hacked.

I understand the fact in general 2FA via SMS is very insecure and weak but that is the case whether its through 3CX or a Cellphone carrier right? nothing to do with 3CX itself but a weakness of the system.

But atleast with SIP trunks / SMS you cannot just steal the SIM / clone SIM card.
 
Thank you for the suggestion.

But if our DID line is used for SMS, how can it be hacked? other than our epabx (3cx) server itself being hacked or a 3cx user account being hacked.

I understand the fact in general 2FA via SMS is very insecure and weak but that is the case whether its through 3CX or a Cellphone carrier right? nothing to do with 3CX itself but a weakness of the system.

But atleast with SIP trunks / SMS you cannot just steal the SIM / clone SIM card.
Indeed, the issue is with SMS protocol itself.

Yes, your SMS is secured from the 3CX to the provider, but after that, it isn't. The receiver's SIM card could be cloned. Thus the weakness of SMS 2FA.
 
Indeed, the issue is with SMS protocol itself.

Yes, your SMS is secured from the 3CX to the provider, but after that, it isn't. The receiver's SIM card could be cloned. Thus the weakness of SMS 2FA.

Thanks for your response.

our use case was the 2FA was going to be inbound not outbound, so other than the 3cx server itself being hacked seems pretty secure.If we intend to receive SMS 2FA codes on the SIP trunk DID lines..
 
So I'm not sure what page you came across that made you think 3CX is priced or otherwise cares about users. But per this page you can see that 3CX is priced per simultaneous call.

And SMS is not delivered via VoIP and has nothing to do with SIP. The SMS will reach whoever is providing the SMS capabilities for the number, which will then be delivered via API to 3CX's 'broker' service which then delivers the message via some method to your 3CX. The reverse happens for outgoing. So while it is not susceptible to SIM cloning there are many hands involved so I still wouldn't consider SMS secure.

As a matter of fact the voice capabilities and the SMS capabilities of a number can be separate. So if you have SIP trunking with a provider that is not on the SMS certified list you can just port the SMS capabilities of a number to a supported provider while leaving the voice portion with your existing provider. We did this for years before we had SMS capability and even after as often folks wanted fancier SMS capabilities than what we could provide.
 
  • Like
Reactions: Evolute IT
You can try it for sure! That would work! Still not the best security but at a certain point, is it really the top priority if you send 2FA to 3CX extensions? I don't think so. It sounds like you need convenience more than security, which I can understand!
 
Status
Not open for further replies.

Latest Posts

Members Online Now

Forum statistics

Threads
111,831
Messages
589,276
Members
164,660
Latest member
RJenkinsROCK