FQDN and failover

Status
Not open for further replies.

IanT

Customer
Joined
Jan 2, 2020
Messages
4
Reaction score
0
Hi , new to the world of 3cx , I have been tasked with the job of getting High Availability working on a
clients 3cx.
The setup is as follows the client has the active and passive servers on the same subnet, behind the same firewall (Sophos SG) . We have tested the failover and the phones and ATAs all registered to the Passive
server on failure of the Active server . The problem was that the although we could make outbound sip
calls, we could not get any inbound sip calls. My belief is that the fault was caused by firewall nat rules on
the Sophos , which point to the IP address of the active server .
When I picked up this job, HA had not been setup by the installation engineer, so I have made progress in getting HA to the point described above , just not sure how to resolve the final issue with the sip calls . Also
I have no knowledge of the Sophos firewall , so no idea of what it's capabilities are !
Any pointers/help from anyone who has experience of HA on 3cx would be greatly appreciated .
 
Ive used 3CX with Sophos before and they were a bit of a pain to setup. However please clarify if you are using HA with Enterprise licence or the HA that comes with the PRO licence (I believe this version is legacy however need to check).

If Enterprise it is a single licence key which can register to 3CX's servers twice. More information can be found here: https://www.3cx.com/docs/failover/

One other question - is your provider IP authenticated or Registration based as this will be a major factor.
 
Hi thanks for getting back to me , it is using an enterprise licence , recently upgraded both servers to 16.0.676 . The SIP provider is IP authenticated .
 
So they require the public IP address of the PBX configured on their trunking platform (and normally public IP of theirs through the local firewall as well). Has this been done for both servers or are you using redundant trunks or something like that ?

IP authentication complicates things and registration based SIP trunking would be the better option for sure.
 
Yes that's been done for both servers.
The Sip provider is IP auth only .

Just to recap when I took over this project it had been left the active server up and running so everything phones and call wise worked but the fail over didn't work . The engineer who installed it, said that everything was complete and the fail over tested . The passive server wasn't restoring from the backups on the Active server . The Passive server was on an outdated software level , so the only fix for that was to upgrade both servers to level 16 .
 
This is a common issue - because the NAT/Port Forward entries are pointing at the other server.

You'll need to do something like:
  • Have the firewall ref the port forwards by FQDN instead of IP
  • Use another public IP on the failover server and have your SIP provider send invites, etc to the other IP during failover. That IP will have port forwards to the failover server.
  • Get creative with scripting and update the firewall rules via script, call script during failover
  • Get real creative with scripting and update the failover PBX IP address during failover
  • Some other method of getting the open ports to point to the failover PBX.
 
  • Like
Reactions: eddv123
Status
Not open for further replies.

Forum statistics

Threads
111,935
Messages
589,823
Members
164,816
Latest member
natedog