Networking / QoS question

Status
Not open for further replies.

Chris A

Bronze Partner
Advanced Certified
Joined
Jul 6, 2020
Messages
49
Reaction score
6
I have two questions:

1. Of the ports below which should I enable QoS on if my PBX is located in the cloud? I want to make sure call quality isn't affected by heavy bandwidth usage
2. Of the ports below, can I lock any of these down to just my SIP trunk providers IPs?

Does 3CX have any info on bandwidth usage on the items below?

2020-09-30_10-44-19.png
 
Any networking guru's on here? I am curious if anyone has any details on this? I did a few packet captures on my SonicWALL and I don't ever see any inbound traffic on port 5060 to my 3CX instance, it all seems to be outbound from my 3CX server to the WAN. I am really trying to wrap my head around what REALLY needs to be open to the public internet vs what I can lock down.
 
My setup is utilizing a VPN tunnel from my data centers to a remote location. The 3CX Windows instance resides in our data centers and is accessed via handset devices via the VPN tunnel or the occasional SBC. I had 2 questions in regards to my "cloud" hosting setup.

1. Where I could apply QoS
2. Security / lock-down from incoming WAN / VPN connections (this is where my SonicWALL comes into play)

I think I got things working as I wanted with only 443 & 5090 open to the WAN. I then opened 443,5001, 5060, 9000-10999 for incoming traffic over the VPN tunnel from my various sites with the handset devices. I don't lock down outbound traffic from the 3CX Windows instance.

That article seems to answer a lot, thanks!
 
Of the port list sent through, for QoS disregard everything but the SIP and RTP traffic (ports).The main problem you have when it comes to QoS in this setup are 2 layer 3 devices plus VPN.

For the most part tagging of VLAN and QoS packets are removed when off of the layer 2 (switching network) for the most part I think you can do the following.

1) Enable QoS policies on the server (guide servers outdated now but the setup still applies): https://www.3cx.com/blog/voip-howto/qos-windows/

As far as your data centre is concerned (and only you can answer this) the traffic here will be mostly used for voice, so concentration on the remote site is important.

2) On the remote side split using VLAN's for PC's and phones and apply QoS policies for priority of Voice VLAN traffic (most devices now support both Voice VLAN and LLDP-MED configuration as standard.

Once you get to layer 3 however these tags are stripped, you can use diffserv however I doubt this is much use on a VPN connection since the traffic is encapsulated/encrypted.

Note: If splitting VLAN's data/voice and using webclient in conjunction with desktop phones you will need to enable some sort of intra-VLAN routing.
 
  • Like
Reactions: Evolute IT
Please note that the HTTPS port (443 or 5001 depending on your setup options) should be open, especially for 3CX deltop/mobile clients, Bridge Presence, Remote IP Phones from outside your LAN and 3CX WebMeeting functionality.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,964
Messages
590,007
Members
164,870
Latest member
nizammoktar