Remote users

Status
Not open for further replies.

Lusk

Forum User
Joined
Apr 8, 2018
Messages
68
Reaction score
1
Hi all,

The literature for 3CX says that whenever using a phone across the WAN, then you need to use either STUN or install SBC at the remote site.

My question is: what is to prevent someone from simply adding the 3CX server's IP or FQDN to the remote equipment and then allowing the remote phone to connect directly to 3CX in this way?


Is this an issue doing this?
 
The SBC uses port 5090 by default, and Direct uses 5060, STUN can use 5060, 5065 and so on. if the ports on your router are not open or if you change the default ports while installing, remote users would not know and or could not connect to the PBX.
 
  • Like
Reactions: Lusk
Stun config is connecting directly to the 3CX server, using different SIP / RTP ports.

If you configure the settings within 3CX, there have to match on the phone

Another option for WAN, setup a site to site vpn and then configure the phones as local.
 
My question is: what is to prevent someone from simply adding the 3CX server's IP or FQDN to the remote equipment and then allowing the remote phone to connect directly to 3CX in this way?
There are passwords involved, it is not simply a matter of knowing the IP. Hackers are constantly attempting to register devices, and place direct calls to, and through, 3CX (and other VoIP PBXs), 3CX is very good at shutting these down.

https://www.3cx.com/docs/voip-security/
 
  • Like
Reactions: Richard P OConnor
They have to be authenticated. You will see a lot of people trying to register phones for sure. You could get aggressive with a firewall policy and only allow remote peer addresses that you specify.
 
  • Like
Reactions: Richard P OConnor
Stun config is connecting directly to the 3CX server, using different SIP / RTP ports.

If you configure the settings within 3CX, there have to match on the phone

Another option for WAN, setup a site to site vpn and then configure the phones as local.
Yes, understood about the VPN.

Presumably though there is nothing to prevent you from configuring the phone directly across the WAN through to the 3CX server? The only downside would be if the config changed on the server then the phones have to be re-configured.
 
Auto-configuration is based on the MAC address of the device, amongst other things.
 
Yes, understood about the VPN.

Presumably though there is nothing to prevent you from configuring the phone directly across the WAN through to the 3CX server? The only downside would be if the config changed on the server then the phones have to be re-configured.

You may want to re-watch the certification videos as some of these questions are very basic and should have been covered en-route to your intermediate cert. Yes you can manually configure your phones, but why would you if you can provision them? The only time that should be necessary would be if you weren't using a supported device.
 
  • Like
Reactions: NicholasP_3CX
You may want to re-watch the certification videos as some of these questions are very basic and should have been covered en-route to your intermediate cert. Yes you can manually configure your phones, but why would you if you can provision them? The only time that should be necessary would be if you weren't using a supported device.
Thanks for the reply.

That is a good idea to review the video again, shall do.

There are two points here: firstly, as I have proven, the fact that anyone has a qualification, this just can not be substituted for experience. Secondly, I do not recall seeing in the videos whether it was actually mandatory to set up SBC or STUN.
 
Secondly, I do not recall seeing in the videos whether it was actually mandatory to set up SBC or STUN.
If the devices are not at the same location as the server (or hosted setup), then there are four methods to connect them....STUN, SBC, VPN, or, in the case of 3CX software devices, the 3CX Tunnel. The SBC also uses a tunnel connection.
 
If the devices are not at the same location as the server (or hosted setup), then there are four methods to connect them....STUN, SBC, VPN, or, in the case of 3CX software devices, the 3CX Tunnel. The SBC also uses a tunnel connection.
Thanks.

If you did not use STUN, SBC and went for VPN, you'd presumably use a local IP to connect across the VPN but would there be anything to stop you using a VPN and just using the WAN IP?
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,953
Messages
589,915
Members
164,851
Latest member
DrunkeMeister