I have 2 ISP providers, how can I automate the way 3CX updates the static IP in the event the main ISP fails?

Status
Not open for further replies.

greychain

Gold Partner
Advanced Certified
Joined
Jul 13, 2018
Messages
779
Reaction score
122
I have 2 ISP providers, how can I automate the way 3CX updates the static IP in the event the main ISP fails?
 
Are you talking about 3CX updating their FQDN? If you have an Enterprise license, that time should be about 5 minutes, otherwise TTL can be 6 hours.
If you anticipate the public IP may change, then best not to set it as static.
 
  • Like
Reactions: Saqqara
That is a different scenario I think where there are 2 3CX servers, this is a single server which has 2 possible routes to/from the Internet. I did think of using DHCP, but am unsure of how the server determines if it's external IP has changed and if it does how often does 3CX update their FQDN records.
 
That is a different scenario I think where there are 2 3CX servers, this is a single server which has 2 possible routes to/from the Internet. I did think of using DHCP, but am unsure of how the server determines if it's external IP has changed and if it does how often does 3CX update their FQDN records.
So, hopefully you did the dual WAN on the firewall and not the machine itself.

If so, simply set the IP to Dynamic in 3CX. It will regularly use STUN to find its external IP of communication. This way, your firewall can failover and the update in, as @leejor said, fairly quick if you have an Enterprise license. Otherwise, the DNS TTL is 6 hours.

Note that you'll need to forward ports on both IPs/interfaces for this to work correctly. Use SD-WAN if possible to make this easier.

If you use a custom FQDN, the DNS itself must take care of updating the A record address.
 
  • Like
Reactions: JohnS_3CX
So users who have standard or pro license really shouldn't use DHCP, as their phone system may be offline for 6 hours every time they get a new IP?

I'll give DHCP a go and see what happens.

Interesting reply from 3CX in another thread , if it's not supported why provide it?

"For anyone else reading this, as already mentioned above, we recommend a static IP both for WAN and LAN for production environments and may also suspend support for issues deriving from the use of dynamic ips and will not proceed until they have been set to static."
 
Interesting reply from 3CX in another thread , if it's not supported why provide it?

"For anyone else reading this, as already mentioned above, we recommend a static IP both for WAN and LAN for production environments and may also suspend support for issues deriving from the use of dynamic ips and will not proceed until they have been set to static."
Let me highlight a few points of the response because I have a feeling that you may be reading it wrong:

"For anyone else reading this, as already mentioned above, we recommend a static IP both for WAN and LAN for production environments and may also suspend support for issues deriving from the use of dynamic ips and will not proceed until they have been set to static."

Very simple actually why this is said, you pointed out one case yourself, if the IP changes, this isn't instantly reflected, so there is a high probability that Remote Extensions might stop registering and calls from/to SIP Trunk providers may misbehave.
We have seen cases where the Primary internet connection was "flapping" every 3 minutes, so IP was changing every 5 minutes.

So, in such cases, very correctly so, fix the network and if you can't control it to behave more stable, set it to static.
 
  • Like
Reactions: Evolute IT
For a once in a while issue, like once or twice a week, then how long before the 3CX FQDN gets updated?
 
For a once in a while issue, like once or twice a week, then how long before the 3CX FQDN gets updated?
STUN requests are sent every 20 minutes from 3CX (can be reduced to 5 minutes but no less). Once an I change is detected, it immediately changes the 3CX FQDN and updates the Public IP of the system.

At this point, SIP Trunks should be working OK via the new Public IP.

At the same time, the 3CX FQDN is updated (doesn't work with custom FQDNs..). The TTL for Ent Keys is 5 minutes, and for Pro keys 6 hours.
This means that remote extensions will get updated as soon as 5 minutes after this event.

Keep in mind though that there are some ISPs around the world that ignore TTL and cache FQDNs for 3-4 hours, so if a end user is behind one of these ISPs, there isn't much we can do.
IT very often though helps to have the Primary DNS of the PCs set to Google DNS.
 
  • Like
Reactions: Evolute IT
"This means that remote extensions will get updated as soon as 5 minutes after this event." So for PRO it's every 6 hours?
 
"This means that remote extensions will get updated as soon as 5 minutes after this event." So for PRO it's every 6 hours?
Correct

[EDIT]
Up to 6 hours for the TTL, if end user is on an ISP that overrides the TTL we set, then maybe more, but as I said, that we can't control 100%...
 
Thanks, one more question. If I have a static IP and manually change the IP to the second ISP, will it take 5 min for ENT and 6 hours for PRO for the external extensions to be updated?
 
If you have the money and want to do this "correctly"

Custom FQDN
The FQDN points to a VIP (Virtual IP)
The system behind the VIP knows the real public IP of 3CX
Your failover device can update this system when IP changes
No changes are needed to the FQDN, it's still correct on a failover because the VIP doesn't change.
Said system typically can update in seconds and since it's the only thing that needs to know the real IP, no caching, updates, etc. matter.

(Congrats, I've just described part of how SD-WAN works/is setup)

However, some people care more about money instead of reliability so that's where you either pay 3CX (enterprise with 5 min ttl), use custom fqdn (you control the ttl on your end but you have to make the system), use pro, etc.
 
Yes I thought of using a Watchguard T80 to do this. Protection plus reliability.
 
Thanks, one more question. If I have a static IP and manually change the IP to the second ISP, will it take 5 min for ENT and 6 hours for PRO for the external extensions to be updated?
Yes, the FQDN to update will take the same amount of time.

I agree with what @SweetAction said, it really depends on how "mission-critical" this system will be, and what the budget is.
If you e.g. simply want to install 3CX for a customer that has spotty internet on their premise, install 3CX in the Cloud (Hosted by 3CX, Google, AWS, etc...), then for IP Phones use an SBC and for Desktop Apps, Mobile Apps, etc, they will see a short drop in their connection when the internet fails over to the secondary WAN, then reconnect.
 
  • Like
Reactions: Evolute IT
Thanks everyone for clearing this all up.
 
  • Like
Reactions: NickD_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru