3CX on AWS connected by VPN to office

Status
Not open for further replies.

pitrickzul

Platinum Partner
Advanced Certified
Joined
Mar 13, 2018
Messages
126
Reaction score
17
Hey guys,

I have a 3CX that is installed in AWS. I installed another VM for my OpenVPN Access Server. Now, i connected my router to the OpenVPN sever, added a subnet between both VMs in AWS and so far, everthing is good.

I provisionned a T41S with a LAN config, the phone provisions, the only issue is that 3CX can't really manage the phone (reprovision, reboot, firmware, etc) and it's obvious because well my router can connect to the 3CX via the VPN server but the pbx can't see the router which is normal.

I would really like to be able to achieve this. We have to deal with a few technicalities here and i would sell this product even better if i was able to make a 3CX "On premise" via AWS, I know i can't install a openvpn client on a 3CX vm because as soon as you enable the vtun, the SIP server goes down since it's not supported.

Anyone have any ideas?
 
Can you confirm you have a routed (no NAT) VPN connection between the T41S and the 3CX instance?
 
no, the VPN connection is between the T41S and a VPN server on another VM in the same subnet in AWS.

essentially, the T41S will be able to ping the 3CX's LAN IP but not the other way around. I know this is my problem. I just can't think of a solution.
 
My guess is that your 3CX server does not use the OpenVPN box as it's default gateway, so it does not know where to send the traffic. To make this work you will need to add the route for your phone LAN network on the 3CX server so it knows to hand that traffic off to the OpenVPN box instead of the AWS default gateway.

I'd be inclined to use an AWS VPN between your 3CX instance and your premise network. Less complexity and it would be supported. However, there would be a monthly cost - which is why the option route works so well. But, if you have 100+ phones at this site paying for a VPN might be the best option. (I have heard 3CX will be releasing new SBC code that will support up to 100 desk phones - currently the supported limit is 50. But you can use several SBCs at a site to spread the load.)
 
Nah that's not it, at least I don't think so. If it provisions and works then traffic is making it back and forth. Can you hit the 3CX web interface from the same subnet as the PBX (via the VPN tunnel)?
 
i can log in the PBX on it's AWS LAN IP from my office, yes.
 
So i tried something else.

I configured my router as the openvpn server. I created a 2nd network interface on the 3CX AWS machine so that way the 3CX wouldnt use the same NIC for both 3CX and the VPN but even if i force 3CX on eth1, the SIP server doesn't want to start.
 
Bump.

I don't want this thread to timeout and die as I am in a similar (~ish) situation - I have AWS EC2 instance with a site to site VPN to a Sonicwall and would like to plug in phones on prem and they directly speak to the AWS PBX. But I will create my own thread for that... Maybe our threads will help each other?
 
We're wanting to do the exact same thing. The thing is we need to create a network on the AWS side and have the 3CX use that network as a gateway out to the VPN which needs to be on another VM from what i am gathering.

I was successful in connecting a phone via LAN to a AWS hosted 3CX. The issue was that the 3CX couldn't control the phone. It saw it but was unable to pass commands like reboot, firmware, etc

For this to work the 3CX needs to be the client to a VPN server which would be your router at the client's side but as mentioned earlier, when you connect a 3CX running VM to a VPN, the SIP server shuts down because it appears to not like the VTUN NIC the VPN created.
 
Just to clarify. 3CX should have zero VPN interfaces. It doesn't need to be a 'client' to a VPN server. 3CX doesn't know or care about network topology. It sends traffic to the network stack and lets the OS route from there. You don't need 3CX to use any VPN as a gateway. Your 3CX instance should simply have a default gateway out to the internet. That gateway should have a route to your remote subnet over the VPN tunnel (site to site, no NAT). As long as your routes are in place and there's no NAT in between you should be fine.
 
  • Like
Reactions: accentlogic
Status
Not open for further replies.

Forum statistics

Threads
111,914
Messages
589,712
Members
164,785
Latest member
Texas Clay -