How do net2phone and others do it with no sbc?

Status
Not open for further replies.

AGidi

Gold Partner
Basic Certified
Joined
Jun 30, 2017
Messages
96
Reaction score
20
We are trying to win an account that runs net2phone 25 ext per branch office , no SBC.
I Also have a colleague That does telephony renting asterisk based Pbx’s with some sort of web GUI, he sends the phones to the clients , stun ,no sbc.

the clients use several brands of regular telco modem routers. Nothing is touched on the client side. no vpn.

so how come they can and we can’t?
 
Net2Phone has a SBC, it's just not on the client side. 3CX doesn't require a SBC. In a perfect world, you don't need a SBC. But if you want to make sure it works 100% of the time, you use a SBC.
 
How does an SBC outside the NAT work? I did not check but do they VPN each phone?
 
Couple ways to handle this.

1) STUN when networks are configured correctly.
2) Server side SBC, for example NATPASS.
3) Have the phones build a tunnel back. Did you know Yealink phones have a OpenVPN client built in? Easy to configure, then the phone makes a VPN tunnel back to the hosted system. (This is how the mobile apps work btw, they build (non OpenVPN) tunnels to 3CX server)

Options 2 and 3 are totally unsupported by 3CX btw.
 
I´ve seen phones with VPN client onboard (we don't use those) .
Hopefully in the near future if the hardware supports it, and since 3CX re writes the Firmware it could work similarly to mobile apps?

I´ll read on NATPASS
thanks
 
on Number 1. what are the cases que STUN fails on a regular residential / commercial Cablemodem or ONT? Lack of ______?
 
STUN need to have no SIP ALG, Static IP for each phones, RTP range 12 ports for each phone not overlaping, SIP port unique for each phone, NAT rules done on remote router/firewall residential box
 
Based on experience with 250,000 active customers, we are recommending that cloud deploys with remote phones go with an SBC. Now you can look at your friend with asterisk and his customers and argue otherwise. But we can say based on facts that your customers will be happier and easier to support when deployed with one SBC for the office. Its not a matter of not being able to do it with direct STUN.
 
STUN need to have no SIP ALG, Static IP for each phones, RTP range 12 ports for each phone not overlaping, SIP port unique for each phone, NAT rules done on remote router/firewall residential box
I'm going to take a minute to address this, as there is a lot of misconception about this.

On a remote side the phone does NOT need a static IP, does NOT need port forwards. These steps are often taken because the upstream device is not "stun friendly". If you have proper upstream devices, STUN can be 100% plug and play.

Yes, SIP-ALG needs to be off, the router needs to preserve ports, they need to be unique ports. But it can be done.
 
  • Like
Reactions: AGidi
My answer for STUN mode was on most common case you got on residentitial box as Agidi was speaking about and not in an office with professional devices with unknown features on ISPs box.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,964
Messages
590,000
Members
164,869
Latest member
hpgitsupport