Failover / multiple IP and remote devices

Status
Not open for further replies.

CRM250

Customer
Basic Certified
Joined
Dec 3, 2020
Messages
20
Reaction score
3
Hello all, first time poster so go easy on me.

So i am currently running 3CX and being a relative newcomer to phone systems i admit i am battling with a couple of things.
My SIP provider is Gamma, and i have a fail over plan (2 separate WAN IP's)
Firstly it does seem a little backward if Gamma doesn't support a FQDN over static IP's - or am i wrong here and they do support FQDN targets instead ?

My setup is a simple system hosted on premise with a mixture of desk phones on premise, and remote desk phones on site (home workers at the moment as you would expect)
It works perfectly well like this and that is all good - however adding a "hot" copy ready to kick in should the primary site go down, is not so easy.
I have cloned the VM running the main 3CX to the other site, and with a couple of adjustments, it all works ok and voice is 2 ways and while the devices take a while to sort themselves out, it does work.
Obviously i think a SBC would be advantageous, but trying to find examples, scenarios or even diagrams that don't conflict, and actually make sense is proving a challenge.

Does the SBC need to be on a separate network from the Primary Site ? assuming it does because if the primary link fails - so does the SBC so how does the Secondary site know to kick in ??
Do ALL the ports point back to the SBC or just 5060 ?
Do the remote IP desk phones talk back to the SBC or the main 3CX box ? and if so what ports apart from 5001 (for supported devices, but what for unsupported devices and http manual config)

So to sum up as an example here is the current network (all IP's changed for common sense sake)

Primary Site
WAN = 88.77.66.55
LAN = 192.168.10.0/24
FQDN = 3cxprimary.example.com
3CX box = 192.168.10.1
Gateway = 192.168.10.254

Secondary Site
WAN = 44.33.22.11
LAN = 192.168.20.0/24
FQDN = 3cxsecondary.example.com
3CX box = 192.168.20.1
Gateway = 192.168.20.254

Also note there is a IPSEC site to site VPN between the 2 sites.

The deskphones are mostly in the primary site (Office)
There is also around the same number of desk phones in various locations at users homes.
Most hand sets are either Polycoms (Unsupported VVX600) or supported Yealinks

So some real world configs or tips would be very welcome, routers are Drayteks (they can be a challenge but i got those all sorted) i have seen quite a bit confusing 3cx and conflicting documentation, if i can get all this working i am more than happy to publish if it helps someone else trying to achieve similar that is seamless and automatic.
 
Hi,

>Does the SBC need to be on a separate network from the Primary Site ? assuming it does because if the primary link fails - so does the SBC so how does the Secondary site know to kick in ??

Yes, you don't run an SBC on the primary site, there is literally no point to doing so because local phones talk directly to the PBX LAN IP

>Do ALL the ports point back to the SBC or just 5060 ?
>Do the remote IP desk phones talk back to the SBC or the main 3CX box ?

Which ports? The phones talk to the SBC, not the PBX so that's where everything goes. Only exception is 5001 for provisioning, that goes back to the PBX always
So if setup as SBC phones they just talk to the SBC. If remote (referring to remote STUN), they always talk to the PBX FQDN and are unaware of the SBC.

>Also note there is a IPSEC site to site VPN between the 2 sites.

This can complicate things OR make them simpler we can elaborate further on this later

I would ask though what is the goal you want to achieve?
- Simple failover for the PBX machine in case it stops?
- Or failover to keep at least 1 site connected to telephony in case the other site loses its internet link?
 
John - many thanks for taking the time to reply

My feeling was correct on the SBC location then, away from the primary site or sat in the middle so to speak - so long as its got connection to both Primary and Secondary 3CX nodes.

The goal is simply to have a fail over solution, automatic would be prefered - however a bit of DNS editing for a manual fail over solution wouldn't be an issue.
My primary site leased line is very reliable to date, power issues on site are more likely than the leased line failure oddly.
Having a 3CX i can "spin up" on demand is the plan which is what i have done with a clone of the original Windows based 3CX box onto the secondary site which does work - but obviously all the hard wired IP phones struggle with this most likely because of DNS and a long TTL
 
My primary site leased line is very reliable to date, power issues on site are more likely than the leased line failure oddly.

Then since you have a primary site, and a secondary connecting via VPN lets pretend for a moment that its just all a big old LAN. We can drop the concept of remote phones/SBC/STUN altogether and leverage the power of your VPN. We can also forget about public IPs and the public FQDN for now:

- Keep the passive server at the same site as the primary
- Setup 3CX to work with a local FQDN
- Provision your phones on the local FQDN
- Setup a split DNS that points to the active server with a low TTL=60
- Have a script ready on the passive server that changes the DNS entry to point to itself

=> Active goes down > Passive takes over > runs script and points FQDN to itself > Phones across the board will soon register on the backup server.

Assumptions made:
- The VPN *actually* works as intended, and is transparent (including multicast)
- The phones on both sites see the same DNS server for split DNS to work


Also read this well: https://www.3cx.com/docs/failover/
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,990
Messages
590,161
Members
164,925
Latest member
batarong