3CX with Third Party SBC

Status
Not open for further replies.

amir_

Premier Customer
Joined
Aug 7, 2020
Messages
185
Reaction score
46
Are there any resellers experienced with implementing AudioCodes or any other vendor SBC with 3CX? Currently - we are testing 3CX behind our firewall and to prevent the headaches of making SIP work thru the firewall - I'm recommending that we either move the 3CX onto a public address or we integrate an SBC that sits on our public edge.

It's apparent that most organizations seem to run 3CX on their public edge and there is reluctance here to do that so I'm trying to come up with alternatives.

Thanks,

Amir
 
  • Like
Reactions: amir_
I had the impression that the 3CX SBC was primarily used for allowing remote phone usage. Am I wrong? Can the "3CX" SBC be used, as a tradtional SBC and placed on the public EDGE in front of my 3CX VM?
 
I had the impression that the 3CX SBC was primarily used for allowing remote phone usage. Am I wrong? Can the "3CX" SBC be used, as a tradtional SBC and placed on the public EDGE in front of my 3CX VM?
I think you're misunderstanding the point of the 3CX SBC. It is used so phones on the LAN connect to the SBC, and the SBC connects to the 3CX server that is not on the LAN. So:

phone -> SBC -> tunnels over Internet -> 3CX server in data center

Mobile apps and web browsers connect to the 3CX server not to an SBC. If 3CX and physical phones are on the same LAN there is no need for an SBC.
 
  • Like
Reactions: amir_
Thanks for that clarification.
 
Hi @amir_ , yes, we deployed AudioCodes SBC in the DMZ zone and 3CX behind the AudioCodes SBC.
 
The 3CX SBC was designed to overcome such problems in the first place, that's why we made it. Some of the things it can help with are:

- Bypass Firewall restrictions safely
- Bypass some restrictions by ISP
- Bypass SIP ALG
- Avoid need for DMZ
- Avoid port forwards
- Avoid need for special VLANs
- Avoid needing static IPs on phones
- Keep local calls on the network and avoid using WAN bandwidth
- Prevent some types of SIP attacks because phones are not exposed to the internet

1. You install the SBC on the same internal LAN as the phones, the phones only talk to the SBC.

2. The SBC opens an outgoing connection to your cloud PBX and you are good to go.

This means you can save on the cost of additional 3rd party SBCs, and keep the solution simple without any complex setups ;)
 
  • Like
Reactions: amir_
The 3CX SBC was designed to overcome such problems in the first place, that's why we made it. Some of the things it can help with are:

- Bypass Firewall restrictions safely
- Bypass some restrictions by ISP
- Bypass SIP ALG
- Avoid need for DMZ
- Avoid port forwards
- Avoid need for special VLANs
- Avoid needing static IPs on phones
- Keep local calls on the network and avoid using WAN bandwidth
- Prevent some types of SIP attacks because phones are not exposed to the internet

1. You install the SBC on the same internal LAN as the phones, the phones only talk to the SBC.

2. The SBC opens an outgoing connection to your cloud PBX and you are good to go.

This means you can save on the cost of additional 3rd party SBCs, and keep the solution simple without any complex setups ;)
We have a business mandate to avoid cloud based solutions. We've been down that road before and there is a very good reason Bezos is the richest man in the universe - cloud based solutions are not cost effective in a majority of the use cases. We do 3,000-5,000 calls per day. The last thing I want to do is run that PBX in the cloud.

It would be very nice if 3CX had an SBC solution for on-prem. I would pay for that - given that we are going to pay a third party for an SBC as I don't want to deal with the firewall nonsense - even IF we disable the default ALG in our next gen firewall.

Thanks John.

Amir
 
We have a business mandate to avoid cloud based solutions. We've been down that road before and there is a very good reason Bezos is the richest man in the universe - cloud based solutions are not cost effective in a majority of the use cases. We do 3,000-5,000 calls per day. The last thing I want to do is run that PBX in the cloud.

It would be very nice if 3CX had an SBC solution for on-prem. I would pay for that - given that we are going to pay a third party for an SBC as I don't want to deal with the firewall nonsense - even IF we disable the default ALG in our next gen firewall.

Thanks John.

Amir
Hi,
I don't think that 3CX will provide a SBC for your needs.
I don't know if you know ProSBC from TelcoBridges which is a very nice solution with a low price (500$ /year). I use it for my business with many 3CX behind it.
 
  • Like
Reactions: ipt_dude
Status
Not open for further replies.