- Joined
- Oct 1, 2020
- Messages
- 6
- Reaction score
- 0
There seem to be a lot of opinions on the placement and use of SBCs, but there is only one configuration that makes sense to me for a local 3CX installation.
If Mobile and 3CX clients do not/cannot use the SBC, and you have to connect to the 3CX server directly, then I don't see how the 3CX server should not be in the DMZ unless you do not use these features? This would also be appropriate if you have one-off remote desk phones connecting through a direct SIP connection.
The SBC should be installed LAN side. LAN Desk phones should communicate through the SBC to the 3CX server and 3CX communication to the LAN should be restricted to the SBC only via firewall rules. This way if 3CX was compromised, they would also need to compromise the SBC to gain access to the LAN. Even though 3CX keeps us informed of phone firmware updates, I trust the security of 1 SBC/target rather than multiple phone firmware.
Additionally, desk phones are the switch for our desktops, so they have to be physically connected to the LAN in some way shape or form. Yes, you can configure then to a VLAN, but that a false sense of security. If the phone is compromised, changing the VLAN configuration on the phone is trivial and now the hacker has potential access to other areas of the network - another reason to keep them behind the SBC. Also, I've read of some using the SBC for phone discovery and moving the phone to communicate with 3CX directly after discovery, but I feel this is a bad idea as I've explained above.
So - aside from security paranoia and a somewhat complex initial setup, why would I not want to configure my network this way?
Is there something I am missing or haven't thought of?
Is there some limitation of the SBC that I should be aware of?
Any help/guidance is appreciated.
Thank you
If Mobile and 3CX clients do not/cannot use the SBC, and you have to connect to the 3CX server directly, then I don't see how the 3CX server should not be in the DMZ unless you do not use these features? This would also be appropriate if you have one-off remote desk phones connecting through a direct SIP connection.
The SBC should be installed LAN side. LAN Desk phones should communicate through the SBC to the 3CX server and 3CX communication to the LAN should be restricted to the SBC only via firewall rules. This way if 3CX was compromised, they would also need to compromise the SBC to gain access to the LAN. Even though 3CX keeps us informed of phone firmware updates, I trust the security of 1 SBC/target rather than multiple phone firmware.
Additionally, desk phones are the switch for our desktops, so they have to be physically connected to the LAN in some way shape or form. Yes, you can configure then to a VLAN, but that a false sense of security. If the phone is compromised, changing the VLAN configuration on the phone is trivial and now the hacker has potential access to other areas of the network - another reason to keep them behind the SBC. Also, I've read of some using the SBC for phone discovery and moving the phone to communicate with 3CX directly after discovery, but I feel this is a bad idea as I've explained above.
So - aside from security paranoia and a somewhat complex initial setup, why would I not want to configure my network this way?
Is there something I am missing or haven't thought of?
Is there some limitation of the SBC that I should be aware of?
Any help/guidance is appreciated.
Thank you