Just want to add that there are a few things you should keep in mind:
• When setting up a 3CX Failover configuration we always recommend deploying the passive instance first. This is due to the fact that you have to deploy the machine first before switching over to passive, meaning that if you already have a PBX running, installing the new PBX to have it act as the passive server will update the DNS record automatically to
its IP. This provided of course that you're using a 3CX FQDN.
• DNS TTL will also play a role here so bear in mind that for the ENT license DNS TTL is 5 minutes whereas for PRO and STD it is 6 hours. If you manage the network for all 3CX remote sites you might want to consider configuring them to use Google's DNS to speedup DNS global propagation.
• The default template we have for Flowroute sets them up as a Register based SIP Trunk so there's a good chance they do not need your IP to authenticate but contacting them to make sure would be a good idea.
• Regarding how it works, to put it simply the Passive server monitors certain 3CX Services of the primary server and will automatically switch itself to active if one or all of those services stop responding so there's nothing you have to do manually if it was setup properly to begin with such as setting up scheduled backups on the primary and scheduled restore tasks on the passive to keep it up to date in regards to configuration.
You might want to check out the guide here:
https://www.3cx.com/docs/failover/
I hope you find this information useful. Do let us know if you need anything else.