LAN & WAN IP changes will affect on 3cx Server

Status
Not open for further replies.

hunger

Free User
Joined
Apr 16, 2020
Messages
24
Reaction score
0
Hi Team

our 3cx Server is on-premises installed on windows server 2016. connected to Patton SBC Gateway.
We need to change IP address of 3cx Server & Patton Gateway.
Can we change LAN IP and WAN IP of the 3cx server and then can change from 3cx Management console (will Management console open after change of LAN IP & WAN IP)
Will it required to re-install 3cx server or Just we can change on 3cx server then from Management console will enough?

re-installing will be very time consuming which will be difficult in production environment.

Could anyone advice on this, or share experience.

Thanks
 
Hi.

Reinstall will not be needed, but services restart, and your PBX console will identify once the IP is changed and offer you that too.
Now once services will be back, you have to keep in mind that if you had devices that were counted to the PBX with the local IP, it is now changed, therefore you will have to reprovision all the phones/gateways too.
 
Are you sure this is a Patton SBC Gateway and not an Analog or PRI gateway?

Are the phones mostly local or remote? if remote how are they connected (SBC/STUN/VPN?)

Are you using a 3CX FQDN or your own?

What model phones are you using?

Changing the LAN IP would require all local phones to need to be re-configured
You would have to re-configure the Patton connection in 3CX and re-configure the Patton
Remote phones depending on how they are configured might just auto reconnect
 
Thanks @CentrexJ for your comments

Thanks @OlegR_3CX for your message


Yes Patton SBC Gateway which directly connected to ISP Router, and we configure gateway from 3cx (PBX) Server which is using SIP lines of 200 channels.

We have both Local and Remote users, Remote users are using with STUN , WAN/VPN but as we move to New Infra then we need Remote users to connect only via VPN for calling, management console, web-client. What could be ports need to allow for other than this (5060,5090,5001,443 & 9000-10999). For RTP Ports do we need to allow for 3cx RTP or Patton device RTP (6000-9999)?

We have our company name in FQDN with ae (UAE). But could you plz let us know what is 3cx FQDN?

We're using only softphones or web-client

Yes, We need to change IP of 3cx PBX server in Patton device (SIP Interface as a remote ip of 3cx server). Route and dns-client. dns-client (we can add our DC server IP right?)

Thanks for your queries.

What could be best process to apply 3cx LAN IP then open Management console and select new LAN IP and WAN IP then restart the services or server will be enough?

And other than this Firewall config's to allow traffic between 3cx server to Patton gateway, Local & Remote users to 3cx server

After migration update to 3cx clients from APP to re-provision with New server IP?
 
Can u plz also highlight some points on FQDN, how we Need to config? after changing LAN & WAN IP

I mean, what config it works for DNS resolving FQDN?
 
Hi team

Any advice
 
Hello @mdshams

regarding your questions:

. For RTP Ports do we need to allow for 3cx RTP or Patton device RTP (6000-9999)?
>> No, ports that need to be allowed on the report firewall for the RTP are 9000-10999 (10500 -10999 are used for the WebRTC in specific). You can see more on the ports forwarding here

We have our company name in FQDN with ae (UAE). But could you plz let us know what is 3cx FQDN?
>> If you wish to use your OWN FQDN, you need to select it during the installation and it must be self-hosted/on-premise install then.
I am sure you know that 3CX offers you free FQDN and this is what it means 3CX FQDN.

Once you change the local IP address of the PBX, you must restart the services, the actual PBX console will notify you of the IP being changed and in order to apply services will be restarted. Because of that, if you had any local devices that were provisioned over the IP, will be to be re-provisioned, each one manually.
If you had a mobile application, send a new welcome email but normally, they will get reprovisioned on the startup if external to the PBX network (since they communicate to the PBX over the FQDN anyway)
 
Hi @OlegR_3CX

I made a Try to change LAN IP and WAN IP

  • Changed LAN IP settings and connected to New Network, Restarted the services and open Management Console.
  • Selected New LAN IP and Dynamic for Public IP (But it took a lot of time, so I made this static and entered Public IP).
  • Restarted the Services, Now Management console dashboard detected latest Public IP and FQDN.
  • I'm started able to resolve FQDN with public ip from local server and from local Network.
  • But as we didn't enter private ip of 3cx server in our AD(DNS Records) it was not resolved with private IP.
  • Whoever connected with LAN Network or VPN they able to ping and nslookup (DNS resolving) with Public IP
  • Unable to access FQDN from LAN network or VPN, Able to access only from server.
  • Also tested to send Welcome Email to clients but didn't reach. Also tried directly scan QRcode from LAN to server didn't work.

  1. Could you please Advice here as is it must needed to make DNS Records in our AD(DNS Server) for FQDN with 3cx Private IP?
  2. Why Welcome Email didn't reach to clients where server outbound is fully allowed and internet is reachable.
  3. If FQDN Resolves with public IP will our LAN and VPN can't reach to this FQDN?
  4. As we prefer only from LAN and VPN connections no port forwarding Done for WAN/Remote connections.

Thanks & Regards
 
Last edited:
needed to make DNS Records in our AD(DNS Server) for FQDN with 3cx Private IP?
See: https://www.3cx.com/docs/creating-fqdn-split-dns/

If FQDN Resolves with public IP will our LAN and VPN can't reach to this FQDN?
It should work if you use NAT Reflection in your router. Otherwise many routers don't allow accessing the WAN IP from the LAN. But if you use split DNS (above) then LAN clients resolve the hostname to a LAN IP.

Why Welcome Email didn't reach to clients where server outbound is fully allowed and internet is reachable
Was anything logged? Are you using a custom SMTP server or 3CX SMTP server?
 
Hi @SteveITS

Thanks for your comment


Sure, Will Add DNS HOST Entry.

Regarding SMTP it was figured out, gmail was not reachable for outbound rule of 3cx server.

Regarding Patton Device, this device will reach to DNS server to communicate via FQDN or will it directly register
between 3cx server and patton gateway?

After Resolving DNS for FQDN with Private IP. then it will initiate provisioning within LAN and VPN connected clients
right?

What exact ports to allowed between traffic on Firewall policies.

1.3cx Server to Patton Gateway (FQDN/Private IP of server/ports = 5060, 5090, 5001,443) Do we also need RTP ports in this Rule (9000-109999) or (6000-9999)?
2.Patton Gateway to 3cx Server (Is it require policy vice versa for both 3cx server and patton)?
3.Clients to 3cx Server (FQDN/Private IP of server/ports =5060,5090,5001,443) RTP ports required?
4.3cx Server to clients (Is it require policy vice versa for both 3cx server and clients)?


Best Regards
 
Hi @SteveITS

No we only focus on LAN Clients and VPN Clients

Do u still need to check on Port forwarding or Firewall test?

As I give Traffic details in above message, there's no Remote extensions (who's outside LAN or VPN).

Thanks
 
Where are you asking to allow the ports? If you have a software firewall on the 3CX server try disabling it.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet