- Joined
- Jan 12, 2016
- Messages
- 40
- Reaction score
- 7
I currently have this awful split resolution setup where my 3CX install is on pbx.example.com but internally it is 3cx.example.local (.local.. ugh)
So I am setting up a new domain to eliminate the .local.
New domain will be ad.example.com. I imagine this will require me to 'restore'? or fresh install 3cx?
I'd like to use to opportunity to swap over to the Linux iso, but I'd like to also use the same serial key. (This will be in a VM, so should I just make the MAC addr the same as the old windows setup?)
If my thinking is correct... then I will end up with
resolved externally on registrar DNS - pbx.ad.example.com = external ip
resolved internal on domain DNS - pbx.ad.example.com = internal ip? (this should probably just be the external IP just DNAT right?)
However... this becomes a problem if I want to use a certificate (which I do). Or does this?
To fix the internal resolution / public certificate issue, I should use a DNAT rule to take internal requests for the external address and forward them to the internal IP right? This way the cert is still correct and the 3CX server can still reside behind the firewall.
I suppose I could simply bypass this all by hosting the 3CX outside the firewall and using the provided FQDN and Lets Encypt cert... but how does that affect voip traffic on my main net? I suppose I can still VLAN and just would need to allow though the same ports right?
I think I am on the right path, just fuzzy in my head and looking to get some outside advice.
So I am setting up a new domain to eliminate the .local.
New domain will be ad.example.com. I imagine this will require me to 'restore'? or fresh install 3cx?
I'd like to use to opportunity to swap over to the Linux iso, but I'd like to also use the same serial key. (This will be in a VM, so should I just make the MAC addr the same as the old windows setup?)
If my thinking is correct... then I will end up with
resolved externally on registrar DNS - pbx.ad.example.com = external ip
resolved internal on domain DNS - pbx.ad.example.com = internal ip? (this should probably just be the external IP just DNAT right?)
However... this becomes a problem if I want to use a certificate (which I do). Or does this?
To fix the internal resolution / public certificate issue, I should use a DNAT rule to take internal requests for the external address and forward them to the internal IP right? This way the cert is still correct and the 3CX server can still reside behind the firewall.
I suppose I could simply bypass this all by hosting the 3CX outside the firewall and using the provided FQDN and Lets Encypt cert... but how does that affect voip traffic on my main net? I suppose I can still VLAN and just would need to allow though the same ports right?
I think I am on the right path, just fuzzy in my head and looking to get some outside advice.