High Availability with private FQDN and restore process.

Status
Not open for further replies.

Yoann

Bronze Partner
Basic Certified
Joined
Jul 6, 2011
Messages
7
Reaction score
1
Hello,

I'm going to install a second server to enable failover with my new enterprise licence.
My actual server is hosted on one of my Vsphere farm and have a private FQDN and Certificat.

I understand that I have to run the scripts to change the DNS Windows recording and shutdown the active server in case of failure.
My problem is the public adress on this scenario.

Do I have to to use a second public IP for the passive server ?
If so, will I have to manualy modify public IP record on my provider interface ?

Can I use the same public IP for the two server?
If so, I will have to modify NAT on my firewal or use public dynamic DNS.

For the heartbeat, I can use the private IP. But how does the check of the 3 specified services work?
What ports do I have to open between the two servers for the heartbeat check works ?

In case of failure, due to serveur OS or main esx farm fail, when the infrastructure will be operationnal, do i have to reinstall the primary server with backup of the passive or can I just restore a backup of the passive server to keep all the delta data and restart service ?

If I check the failover during 15 minutes, If everything goes as planed, is the only thing left to do is to restart the primary server and modify DNS private/public?
Or do I have other actions to take?

Thanks for your help,

Yoann
 
Hey @Yoann,

I understand that I have to run the scripts to change the DNS Windows recording and shutdown the active server in case of failure.
If the 3CX PBX's are on different networks and hence have different public IPs then yes.

Do I have to to use a second public IP for the passive server ?
Not necessarily but, if they are both behind the same NAT firewall and you want to use the same public IP then what you would have to do in a failover event is somehow automate the firewall rule configuration to switch over to the Passive server. That said, I think it would be much simpler if they had different public IPs which would mean that all you would have to do is automate the DNS record update.

If so, will I have to manualy modify public IP record on my provider interface ?
I'm not 100% sure what you mean here, are the PBXs full public (no NAT) and if so, are you talking about the IP on the VM's network interface?

For the heartbeat, I can use the private IP. But how does the check of the 3 specified services work?
What ports do I have to open between the two servers for the heartbeat check works ?
If there exists local routing meaning one PBX can reach the other via local IP then yes you should be able to do this. The checks are as follows:

• SIP Server: TCP traffic to the PBXs SIP Port port, default 5060.
• Webserver: TCP traffic to the PBXs HTTPS port, default 5001 or 443.
• Media & Tunnel Server: TCP traffic to the PBXs Tunnel port, default 5090.

In case of failure, due to serveur OS or main esx farm fail, when the infrastructure will be operationnal, do i have to reinstall the primary server with backup of the passive or can I just restore a backup of the passive server to keep all the delta data and restart service ?
Yes you should be able to just restore the backup while the PBX is running yes.

If I check the failover during 15 minutes, If everything goes as planed, is the only thing left to do is to restart the primary server and modify DNS private/public?
Or do I have other actions to take?
You would also have to set the secondary server back to passive mode.
 
hello !

Thanks for the reply:

I will use a different public IP for the second server following your advice.

I'm not 100% sure what you mean here, are the PBXs full public (no NAT) and if so, are you talking about the IP on the VM's network interface?

My pbx and the futur passive one are not full public.
I'm talkink of the public IP, manage by public provider, in my case Gandi, which i have to change manually, in case of failure of the active one, to get external softphone, on andoid client, to get able to connect to the PBX in remote.
I was thinkin also of the pstn provider but i forgot that the siptrunk is initiat by the PBX, so no problem of different public IP, if these IP are register/approuve on pstn provider .

Thanks for the ports use for check !
Because, i prefered not to open in all/all betwen the 2 server because, threre will be in different DMZ , even in different datacenter.

You would also have to set the secondary server back to passive mode.
Also, thanks for that, i did not think of that part.

Yoann
 
  • Like
Reactions: ChrisC_3CX
You're very welcome! Let us know if you face any issues when you attempt to set this up.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru