3CX Transcription Engine Server Installation

diplodock

Premier Customer
Joined
Dec 1, 2022
Messages
45
Reaction score
8
Good afternoon! I have a question about installing a transcription server.
Very urgent.
We installed Debian 12 and everything necessary. We copied the installation line into the console. Addressing question:
The system sees
Local IP: 192.168.80.30 - {this is the server address}
Checking IPv4 connectivity... OK: 188.138.56.20 - {this is the router's external address}
Next -

Please choose FQDN/SSL configuration for this server:
1) Use FQDN provided by 3CX and Let's Encrypt SSL certificate
2) Use custom FQDN and SSL certificate

Select option 2
The installation prompts:

Enter your custom OnBoardAI FQDN (must resolve to 188.138.56.20) [example: ai.example.com] :{enter} 3c.mydomain.com
{this domain resolves to 188.138.56.20 in the DNS record}
We receive:
Checking 3c.mydomain.com... resolves to
The FQDN you entered does not resolve to the OnBoardAI Server IP address. Please enter a valid FQDN.

Question: Which address (internal or external) should the domain point to? What does this mean?
 
The FQDN is the one for the AI server you're building, not the 3CX PBX.

Also, I would recommend using 3CX FQDN+SSL instead of all custom.
 
And what ip we must resolve?
External IP on firewall or internal IP of AI server
 
And what ip we must resolve?
External IP on firewall or internal IP of AI server
External IP. Make sure the required ports are opened and forwarded to the internal IP as well.
 
What ports?
Inthe guide only this:

Firewall Configuration​

Open the following TCP ports for inbound traffic to the machine:
  • TCP 61443 – allow only from PBX IP
  • TCP 80 – for Let’s Encrypt SSL certificate creation/renewal; typically this is not necessary if you are using custom SSL certificates
 
What ports?
Inthe guide only this:

Firewall Configuration​

Open the following TCP ports for inbound traffic to the machine:
  • TCP 61443 – allow only from PBX IP
  • TCP 80 – for Let’s Encrypt SSL certificate creation/renewal; typically this is not necessary if you are using custom SSL certificates
Those two ports. They should be opened on your firewall and point to the AI server.
 
And TCP 80?
It's only for Let’s Encrypt SSL....
 
but the docs say - port 61443 only from my PBX.
Why we need to open ports on firewall?
 
but the docs say - port 61443 only from my PBX.
Why we need to open ports on firewall?
The Firewall Configuration section in the guide specifies that the following ports must be open on the transcription server, as these are required for the transcription service to function properly.

Port 61443 is used by the 3CX system to connect to the transcription server. This port should be configured to allow connections only from the IP address of the 3CX PBX machine.

Please ensure the following TCP ports are open for inbound traffic to the transcription server:
  • TCP 61443 – Allow access only from the PBX IP address.
  • TCP 80 – Required for Let’s Encrypt SSL certificate creation and renewal. This port is typically not necessary if you are using custom SSL certificates.
 
Thank you!
I understand
Can we return to the 1st question:
And what ip we must resolve?
External IP on firewall or internal IP of AI server
Which address (internal or external) should the domain point to? What does this mean?
 
  • Like
Reactions: Evolute IT
It would also help if we had a clear understanding of your network layout. Where is your PBX - in the LAN or in the cloud? Where is the Transcription machine? If your PBX is in the LAN, you will almost certainly need to make sure you have split DNS properly set up, amongst other things...
 
  • Like
Reactions: Evolute IT
My PBX on the LAN. AI Trans server is on the LAN too (192.168.80.30). External adress of the net - 188.138.56.20 (router ext/)
Internal DNS resolve to local IP. External DNS resolve external IP
 
If you have (split) DNS correctly set up, then it should work. PBX should connect to the FQDN of the AI machine, and it should resolve to the internal IP, and it should work.
 
But installation ask, that we need to resolve to external ip:
Enter your custom OnBoardAI FQDN (must resolve to 188.138.56.20) [example: ai.example.com]
 
That's what split DNS does, it let's your internal network only resolve external host names as internal IPs. There are other ways to do this of course, like setting your router to direct traffic for the AI box that tries to leave the network back in.

While this talks about how to set it up for the PBX, the same principle can be used for the AI box: https://www.3cx.com/docs/creating-fqdn-split-dns/?utm_source=chatbot&utm_medium=referral

Also - and this is not an encouraged or supported procedure - you can add some entries in the PBX and AI box "host" files so they resolve each other directly to their internal IPs.

A secondary note, if both PBX and AI box are behind the same public IP you might have some trouble getting Let'sEncrypt to work for both.


Now - to go back to what seems to have been your original question: if you use a custom host name and SSL certificate then the AI box will only need port 61443 open internally, but you need to know how to go about creating it, and also how to set up DNS to resolve your chosen host name to the internal IP, whether inside or outside your network.
 

Forum statistics

Threads
112,025
Messages
590,368
Members
164,978
Latest member
FringeIT-Eric