Does an SBC need to be on the same machine as a bridge slave?

DaveWilliams

Trial User
Joined
May 20, 2025
Messages
3
Reaction score
0
I have created a bridge between two 3cx systems and the slave is seeing presence information from the master, but the master is not seeing any presence information from the slave.
Despite this, the bridge is showing as active on both systems and calls are working fine in both directions.
Of particular note, the bridge is configured to use a tunnel. However, the tunnel's SBC does not reside on the slave's machine. Instead it resides on a different machine on the slave's local network. I suspect this may be the problem as, on the master's activity logs, nothing is reported, but on the slave's activity log I am seeing the following warning message: "Registration at YP bridge has failed. Destination (sip:127.0.0.1:5080;lr) is not reachable, DNS error resolving FQDN, or service is not available." which is why I suspect that the problem may relate to the SBC being on a different machine.
Does anyone know if it is a requirement to have the SBC installed on the slave machine, or whether it is possible to configure the slave to have it connect to port 5080 on an IP other than 127.0.0.1, and also whether this is the likely cause of the missing presence information?
I have checked numerous sources to verify that my configuration is correct and, as mentioned above, the bridge does work fine apart from the slave's presence status not reaching the master. I have also not found any documentation indicating a need for the SBC to reside on the same machine as the slave 3cx. But, at the same time, I'm struggling to work out how the slave system goes about finding the local SBC machine in order to establish the bridge, which it seems to be doing successfully! In each system's bridge configuration, I have the "Remote PBX IP" set to the FQDN of the other system, the "Remote PBX port" set to 5090 and the "Remote PBX uses Tunnel" option checked.
 
Regarding your question, if the bridge is connected using the tunnel option, it only handles the registration of the bridge itself—not presence information. Presence updates are communicated over HTTPS and require using the remote system’s FQDN, including the port number if it’s not the default (443).

To resolve the issue, ensure that the 3CX system that is not receiving presence information is configured to connect via the FQDN of the other system, and that this FQDN is reachable over HTTPS from the remote site.
 
  • Like
Reactions: Evolute IT
This has resolved the issue.

I wasn't able to use 443 on the slave network as it is already routed to a web server machine. However, I configured my router to make port 5001 available publicly available, forwarding it to port 443 on the slave 3cx machine (192.168.2.27), i.e. 1747929442891.png
I then changed the bridge 'presence' page on the master 3cx, to include port 5001 - i.e.
1747929598316.png
Subsquently presence information became available on both systems!

Thank you very much for your help, Charles.
 
  • Like
Reactions: Evolute IT
Thanks Charles. I will look at how this can be remedied going forward, perhaps by routing web server traffic through cloudflare.
 
You should directly port forward the specific ports used by the 3CX system on your firewall. Alternative methods will not function correctly.

If HTTPS ports are already in use on the network where the slave machine is located, you can proceed with the following steps:

1. Take a full backup of the current system and download it to a secure location.
2. Shut down the existing machine to avoid conflicts.
3. Deploy a new 3CX instance and restore the backup during setup.
4. During the restore process, assign a new HTTPS port that is available and can be directly forwarded on the network.

Important:
Once this change is made, all SBCs, IP phones, and mobile/desktop apps will need to be re-provisioned to reflect the new HTTPS port and system configuration.
 

Latest Posts

Forum statistics

Threads
111,962
Messages
589,996
Members
164,867
Latest member
swegner