- Joined
- Jan 28, 2021
- Messages
- 93
- Reaction score
- 45
Hey All,
I was wondering if anyone has 3CX sitting in a private vnet whilst using Azure vWAN and Azure Firewall to expose 3CX for inbound connectivity? It seems technically not possible as there is the load balancers in play and no guarantee outbound connectivity will leave on the same outbound IP when using an IP prefix pool on the firewall. Adding an external IP directly to the 3CX VM would work, but doesn't meet our WAF/IPS requirements. We have a requirement that all external web assets be behind some IPS/WAF type device. The other complexity is when branch office traffic translates across the WAN it must route through the vWAN/firewall similarly, though it shouldn't have the same NAT PIP complexity that the external traffic has.
TL/DR
Just wondering if anyone else is doing anything different with 3CX in Azure than pinning a public IP directly to the VM and using NSG rules?
I was wondering if anyone has 3CX sitting in a private vnet whilst using Azure vWAN and Azure Firewall to expose 3CX for inbound connectivity? It seems technically not possible as there is the load balancers in play and no guarantee outbound connectivity will leave on the same outbound IP when using an IP prefix pool on the firewall. Adding an external IP directly to the 3CX VM would work, but doesn't meet our WAF/IPS requirements. We have a requirement that all external web assets be behind some IPS/WAF type device. The other complexity is when branch office traffic translates across the WAN it must route through the vWAN/firewall similarly, though it shouldn't have the same NAT PIP complexity that the external traffic has.
TL/DR
Just wondering if anyone else is doing anything different with 3CX in Azure than pinning a public IP directly to the VM and using NSG rules?