Is this possible?

Status
Not open for further replies.

talesmaschio

Customer
Joined
Apr 27, 2022
Messages
20
Reaction score
4
Hello everyone,

I'm new to 3CX, I recently installed V18 in a Windows 2019 VM. I need help to figure how to set things up, I'll try to describe what I currently have.

VLAN 118 is where the IP phones reside. The 3CX server has a NIC in this VLAN, and this is where the default GW is configured. This VLAN is part of a corporate network, and it reaches the internet through our headquarter's firewall.

VLAN 901 is an "external" network, in the sense that is has no virtual connection to the corporate network, for security reasons, as we have no strict control over what the users install in their phones. This VLAN uses the same infrastructure as the corporate network, but it has no interface in the core switch so it is essencially firewalled. In this VLAN is where all our corporate smartphones are connected. This VLAN reaches the internet through a local ISP, and in its path there is an old Firebox XTM515 that I use to configure a few rules for what can go in/out of this network.

The 3CX VM has two NICs, one connected to VLAN 118 which is also the default gateway. The other NIC is connected to VLAN 901. What I would like to do is:

- Register phones from both VLANs in 3CX. IP phones in the case of VLAN118 and the 3CX app in the case of VLAN 901.
- Use local ISP/VLAN 901 to register the smartphones into 3CX via 4G when they are not under our WiFi coverage.
- During the initial tests I will not use external SIP trunks, but if we move forward I will probably need to add another NIC to connect to the provider.

Can this be done? Can you provide me some guidance? I will certainly call a partner in the near future but in the meantime I would like to try to get things running in order to gain some experience with the system.

See image below.

Thanks a lot. Regards from Brazil.
Tales Maschio

Env.png
 
  • Like
Reactions: Maschio
Thank you for your reply. Can the topic be moved to Network Design?
I tried to register the Android App using the QR code but it doesn't work, says no answer. I will read the suggested docs and also take a deeper look at the manual, and if needed I'll come back here for help.
 
  • Like
Reactions: Maschio
does the 3cx Firewall test pass ? Have you configured the firewall rules on the headquarters firewall, as per url links above

can you access the 3cx management console from the smartphone vlan

on the Firebox XTM515 firewall you need to allow 3cx https port (443 or 5000) and 3cx tunnel port (udp port 5090) out
 
Last edited:
Hello, thank you for your reply.

does the 3cx Firewall test pass ? Have you configured the firewall rules on the headquarters firewall, as per url links above
No, it does not. Some tests pass and others fail. But that's probably because I haven't set up the firewall yet. I will not touch the headquarter's firewall, my intention is to do it through the local ISP (XTM515).

1651090524279.png

can you access the 3cx management console from the smartphone vlan
Yes, I can.

WhatsApp Image 2022-04-27 at 17.15.57.jpeg
on the Firebox XTM515 firewall you need to allow 3cx https port (443 or 5000) and 3cx tunnel port (udp port 5090) out
Ok, will do later when I finishing setting things up from the inside. But from the LAN everything should work, right?

Tales
 
As mentioned above this is a networking issue - 3cx supported networks https://www.3cx.com/blog/docs/network-configurations-supported-3cx-phone-system/

if you are not going to change the corporate firewalll , the 3cx server needs to access the internet via xtm515 so configure the network accordingly

3cx server - network card connect directly to the xtm on IP address range not use add the xtm ip as the default gateway. The other card connect to the core switch without a default gateway on vlan 118

now you can configure routing between 3cx network and smartphone vlan on the xtm - just https , 3cx tunnel port
 
Last edited:
Will try that. I have the default gateway on VLAN118 as I need access to the domain controllers so WIndows can authenticate and download updates etc. Will solve that with static routes.

About having posted in the wrong forum, I'm sorry. If there is an admin reading this, please relocate the topic to Networking.
 
I would not install 3CX on a domain joined machine, just a standalone machine - it does not have to interact with windows domain.
 
  • Like
Reactions: talesmaschio
I understand your point. I will probably migrate for a Linux install soon. Cuz if I keep it Windows I'll have no option but to join it into the domain.
 
Ok, moved to Linux. And here's something interesting that I found, would be nice to know why. If I have two interfaces, which is the case, in order to register the app on a given smartphone I need to scan the QR code at the web interface from the same network as the smartphone or it will fail. Is this by design?
 
Yes it is by design. But the failure is by your network design. The QR code is simply passing information to the app on how to reach 3CX. If the app can't reach 3CX via the prescribed method then it will fail which is due to network design, most likely due to DNS resolution.
 
  • Like
Reactions: talesmaschio
The fact is that those networks are isolated from each other. So I need to generate the QR codes from the correct interface.
 
If memory serves, I think it depends on how you log in to the web client? Meaning, if you log in with a LAN IP it will assume you can use the LAN IP. Split DNS may help with this so you can use the same hostname everywhere and have the IP change based on what network you're on.

In the User->Phone Provisioning there is a setting "Network interface for registration and provisioning."
 
Yes, I noticed this setting in User->Phone Provisioning, that's what made me think the QR code should reflect that interface no matter where you're logged in from. Ok, there must be a reason for it being the way it is...

Anyway I got it figured out, I now have both interfaces properly registering their devices, firewall test is all green (there was a 1-to-1 NAT missing) and I also made a loopback rule so the smartphones connected to WiFi can provision from the QR Code in the welcome email, which points to the server's public IP. Yes, another version of QR code, three different codes depending from where you get them. This one makes sense tho.

Thank you all for the contributions, they were key to allow me start undersanding the basics of 3CX.
 
  • Like
Reactions: VasilisV_3CX
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru