Failover WAN - Configuration Challenges

Status
Not open for further replies.

covtech

Forum User
Joined
Sep 3, 2019
Messages
16
Reaction score
0
We recently moved our 3CX Server to an AWS Instance, which has been working flawlessly. We are now getting ready to install a secondary ISP for fail-over, but discovered AWS limits the Gateway to a set IP - we are forced to use a Cellular Gateway which is Dynamic IP - which makes maintaining our VPN to the 3CX VPC impossible to automate without scripting.

Before we go down that route, is there a way to SECURELY allow our on-prem phones to access the 3CX Server via the AWS External IP instead of through VPN?

Key notes - Our secondary WAN will not have a static IP.
We need access to the phones when the Failover occures.
3CX is in AWS - currently provisioned to the internal AWS IP over VPN.

Ideas?
 
I guess the first question is what exactly are you concerned about securing and what are you security it from?

Generally sniffing of traffic is going to happen on your local LAN. It's not trivial to sniff traffic over the internet.

But a 3CX SBC encrypts traffic. Assuming you are using 3CX supported phones this is trivial to setup.
 
Hi Cobalt,

First, thanks for taking the time to answer my post of questions.

1. We do not currently have an SBC as the AWS server is "On the Same Lan" due to Site 2 Site VPN. So I am guessing we need an SBC to make this work.

2. The part we need to secure are the ports that will have to be open, since secondary wan will have a "Dynamic IP" we will not know what IP the WAN2 failover will use to open it exclusively to it, and it will need to be securely open to allow 3cx to work during WAN Failover.

We are wanting to know the best possible way to allow our Local phones (Polycom SPIP335) to connect to the AWS 3CX server without allowing the world access to the 3CX server. While not requiring manual changes in the event of a WAN Failover.

WAN 1 - Static IP
WAN 2 - Dynamic IP (Static is not possible)
 
As far as end to end encryption, you can configure a load balancer in AWS and make sure you have certificates installed on 3cx server, I believe that will take care of the end-to-end. I think most brand of phones are set to accept secure certificates by default.

What firewall are you using at the main location? This can be accomplished very easily using your firewall and a SDWAN interface or WAN failover. You can also mount many firewall vm's in AWS and you should have no problem doing a dynamic peer. If you use WAN failover, you can have an SBC and have the phones connect to that. There is a lot to explain with these solutions, but you should be able to do it.
 
rgruber - Meraki Firewall.

Meraki - AWS = Single Tunnel
AWS - Customer Gateway requires Static IP configuration to allow VPN S2S to connect - we would have to add the Secondary WAN IP every time it fails over to maintain the AWS tunnel.

Lets focus on one piece of this: How to get the phones to work with the 3CX Server (in AWS) when the VPN Tunnel is down.

Currently they connect via Local IP to the AWS Instance - in the event the tunnel dies - the phones drop offline.

Maintaining an AWS Tunnel direct to VPC is not possible without manual intervention of adding the secondary wan IP during EVERY failover event to the Customer Gateway configuration in AWS. So direct connection to the AWS Server through the external IP is preferred.
 
So I don't know that you answered my original question, at least so far as to why you need the VPN? If you remove the VPN from the equation you would simplify your setup. But if you need to keep the VPN in play then the easiest thing might be a SDWAN service that keeps your IP (we are fans of BigLeaf). Then your existing setup will just work as-is.
 
Here are some links to get you in the right direction without me having a network diagram and configurations. Also, What edition of 3CX are you on? I'm asking because if the below doesn't work and you have enterprise edition, you can setup an active-passive 3CX server deployment and have the second wan address communicate with a second server in AWS. Again, it just depends on how your WAN failover is configured.

https://aws.amazon.com/marketplace/pp/Cisco-Systems-Inc-Cisco-Meraki-vMX100/B01N49IN0S

https://documentation.meraki.com/MX/Site-to-site_VPN/Meraki_Auto_VPN

https://documentation.meraki.com/Ar...SD-WAN/Meraki_Auto_VPN_General_Best_Practices
 
@cobaltit - We do not need the VPN during a fail-over - UNLESS that is the only way to keep the phones up. The ONLY thing we need during a failover event is the 3CX server. I apologize that was not clear.

@rgruber - we are firmiliar with the Meraki VPN and AWS VPN requirements, its simply that the secondary wan is a Cellular (Dynamic IP) service and is not capable of being static - making the AWS Customer Gateway configuration manual or scripted dependant. We are hoping for a more stable less maintenance method.
 
We have also discovered that an SBC is not possible in our environment apparently. The aforementioned Polycom SPIP335 is not compatible:

Limitations
Note that these phones can not be used from a remote location or in combination with a 3CX in the cloud.

Known limitations of Polycom 321, 331, 335, 450, 550, 560, 650 & 670 are:

  1. No PnP Support
  2. No STUN Support
  3. No SBC Support
  4. No Full CTI Support (Make Call Only)
  5. BLF Functionality (on applicable models)
  • No Extension Monitoring
  • No Shared Parking Orbit
  • No Speed Dial
  1. Manual DST Support
  2. No Distinctive Ringing for external, queues or ivrs
 
Checking back in to see if anyone had any suggestions?
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,990
Messages
590,164
Members
164,927
Latest member
tohoken1