Internal & external encryption

Status
Not open for further replies.

Ronin

Basic Certified
Joined
Jan 21, 2019
Messages
176
Reaction score
20
Hello everyone,

We have purchased 3CX and we would like to implemement encryption in our calls (internally/externally). We have asked 4 platinum resellers but none of them wants to support us on that feature.
All of them claim that, external encryption for calls does not work and as for internal calls they just don't seem to be willing to do it.

Our questions are:

1. Are there any resellers that can support us with that project?

2. What is the official answer from 3cx regarding the encryption in external / internal calls? Can this be done?

3. Also will the automatic provisioning be working if we implement encyption and cerificates on yealink phones?
 
Hi Alkiviadis,


External calls: With V16U3 you can now have external calls encrypted (SIP transport and SRTP) but only if your provider supports this though.

Internal calls & provisioning: not yet supported, no provisioning for it - you have to set it up yourself
 
unless you use only 3CX Web Client, Android and iOS APPs, then this is also on extension level encrypted. As John said, to and from the provider is up to the provider if they supported it. You can configure it in the trunk settings.
13258
 
Thank you for your answers!
While our providers supports TLS we can not have a successfull registration and even if we manage to have one , we experience disconnections.
We are currently talking with providers to solve this.
We would like to install certificates on our yealink deskphones and configure everything that has to do with encryption.
Are there any resellers that could support us?
 
You can look here if your current reseller cannot help https://www.3cx.com/ordering/find-reseller/

As for certificates, if you use a root CA that the phone manufacturer already supports you might not have to load certs. The 3CX FQDN based cert is already acceptable by the firmware for supported phones. If the phones are local you will need a split DNS set up so the phones can use the certificate.
 
We used the site you mentioned to find resellers that are close to us but no one would help with encryption the way we wanted.
Thank you for the certification info on the yealinks, we will look into that.
Also, if there are any English or German speaking resellers in the forum we would gladly accept your support!
 
I just went through the brand new roadmap of 3CX for Update 4 to 7 of Version 16.
There's nothing mentioned about improving TLS and SRTP.

Without TLS + SRTP:
It is like sending CreditCard Numbers over HTTP instead of HTTPS to an online shop.
Everybody would say: "Never do this."
But in Telephony with 3CX this seems to be standard......

As Alkiavidis said:
All Platinium Resellers we contacted (one of them with over 300 installations) said: It's not working on 3CX.
That's why they do not use it at their clients and therefore they cannot give paid support on this...

External SIP provider-tests:
Tested with German providers DUS.net and easybell. Both with template from 3CX.
(We know at least DUS to be working with TLS and SRTP on our Asterisk server, so it might not be a provider problem.)
We get DUS to work on 3CX but line is cut after 30 seconds. Alkiavidis has more details.

Internal Phones:
Yealink T42S and Snom M700.
One Platinium said that provisioning of internal Phones does not work any more if using TLS and SRTP internally... True or not, I don't know.

We paid a 128 channel license for 1 year + external support and over 100 hours of internal admin time and still: We can not get live because of TLS.

So you can imagine:
We would be happy, if somebody from 3CX or someone from the community could "prove" that those Platinium Resellers (we will not tell their names) and ourselves do just not have enough experience....

Thanks for anybodies help in advance.

BTW: Sytem-Info:
Debian GNU/Linux 9, SMP Debian 4.9.189-3+deb9u2 (2019-11-11) on local VMWare, Firewall Checker passed, custom template to define codecs and order of codecs.
 
Last edited:
If you want internal encryption you will need custom templates and quite some work. It's doable with Yealink phones on both ends. Remote phones can be tricky depending on setup (sbc, direct, etc). 3cx app - I don't know for sure, last time we did this the answer was no.
It's not cheap, but there are partners who will do it when required.

If you want external encryption - SIP provider has to be capable as well.
It can be even more expensive depending on the provider.

All this to say, technically yes, supported no, expensive yes, and flexible no.

I'd take a different approach if I were you - namely place all voice traffic on a separate vlan and use ACLs to prevent anyone from seeing the traffic. It's like taking plaintext HTTP and putting it in a VPN - the data is readable, but only from the inside which you can't get into. Or 3CX may not be the right fit for you yet - it's all about what the business need is.
 
Thanks for the suggestions.

External:
TLS+SRTP to external provider would be more important than internal, although we know, that we can't tell what is "behind" the provider and the person on the other end of the line...
Would you buy at non https secured shops?

Internal:
VLAN for physical Phone Approach, with or without ACL's: We thought about that, but:
Just plug some old "HUB" between the uplink of a switch and copy all sip traffic with wireshark on a raspberry. Small and hard to find. Some basic infos here.
VLAN != Security/Encryption.....

On PC with Windows:
  • If you happen to have the right network card, VLAN can be enabled. But no way to enable VLAN for one application like 3CX Windows Client.
  • TLS can be configured in 3CX Win-Client and it may work with other non-TLS phones if audio is provided by 3CX server. But I do not know a way to provision 3CX Win-Client automatically with TLS and server audio.
  • Browser uses https: OK safe.
Good old ISDN was more secure than sip, as you needed special hardware to copy. Not just a PC.

As you mentioned, it may be possible at the cost of much work/time and money.
For such a simple, standard technology like TLS in 2019 ......

Anyway: Thanks for your comments !
 
Thanks for the suggestions.

External:
TLS+SRTP to external provider would be more important than internal, although we know, that we can't tell what is "behind" the provider and the person on the other end of the line...
Would you buy at non https secured shops?

Internal:
VLAN for physical Phone Approach, with or without ACL's: We thought about that, but:
Just plug some old "HUB" between the uplink of a switch and copy all sip traffic with wireshark on a raspberry. Small and hard to find. Some basic infos here.
VLAN != Security/Encryption.....

On PC with Windows:
  • If you happen to have the right network card, VLAN can be enabled. But no way to enable VLAN for one application like 3CX Windows Client.
  • TLS can be configured in 3CX Win-Client and it may work with other non-TLS phones if audio is provided by 3CX server. But I do not know a way to provision 3CX Win-Client automatically with TLS and server audio.
  • Browser uses https: OK safe.
Good old ISDN was more secure than sip, as you needed special hardware to copy. Not just a PC.

As you mentioned, it may be possible at the cost of much work/time and money.
For such a simple, standard technology like TLS in 2019 ......

Anyway: Thanks for your comments !

External: Perhaps a PRI or similar would be a better fit then SIP then?

Internal: using a hub would only get you the traffic from the devices between it and the 3CX server. Physical security should help with that.
Additionally 802.1x and some strict port security should help. Or like I said - Yealink phones can encrypt their traffic.

As for desktop clients: a good method for configuring Windows Client is mentioned here:
https://www.3cx.com/community/threads/pre-configuring-windows-client.67080/post-294806
 
Last edited:
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,822
Members
164,813
Latest member
divdigital