SBC advice

Status
Not open for further replies.

Albert464

Customer
Intermediate Cert.
Joined
Oct 21, 2017
Messages
110
Reaction score
9
Hi,
For convenience we would like to send Raspberry SBCs directly to customers without setting a static ip in the LAN, is this possible?

Because in the documentation it says that it must be set, but this means that one of our technicians must always go out for the installation.
If this is not possible, do you have any advice on the working method to avoid our technicians having to leave at each installation?
 
Always set a reserved IP. If you need to go out on-site for that, you should rethink your infra.

Normally, we just set the DHCP reservation remotely, ship the SBC, have them plug it in and we're good to go, since all phones can then be detected easily or at least reprovisioned. No need for a static IP on the Pi itself.
 
  • Like
Reactions: nub and Albert464
Hi Albert,

There is good reason for having a static IP, it minimizes the chances of service outage.

What I could recommend, is to allow the Pi to have a dynamic address at first, and then log in remotely to change it to static. You can easily remote into a local PC, then access the Pi from there. For the few remaining cases where this is not an option, you can send somebody on site.
 
  • Like
Reactions: Albert464
Last 2 weeks , I set a Windows 10 SBC for a customer location which is really far from me (1200 km) and on initial settings my DHCP was set to keep same local IP to SBC mac@ . (everything was fine).

Two weeks after,I sent my SBC to the customer , once connected on customer's LAN, SBC got a new local IP and connected to cloud PBX (I didn't noticed IP was not the same as initial setup)

I added my phones , provisionned and then tried to call and each time i got "forbidden" it was impossible to use phones for outgoing calls.

After having factory resetted the phones, problem was already there and suddenly I thought about IP SBC, I saw it was not the same , so in Windows 10 I set NIC to static ip in network properties and got it back to initial IP set.
Then everything worked like a charm.

So for sure a fixed IP is the way to follow to avoid surprises like mine.
 
Can you not connect to a remote machine, and check out the network settings.

Even running advanced ip scanner should give you some clues on the network setup - 'https://www.advanced-ip-scanner.com/ and then you can get the pi a fixed IP address before shipping
 
  • Like
Reactions: Albert464
Hi Albert,

There is good reason for having a static IP, it minimizes the chances of service outage.

What I could recommend, is to allow the Pi to have a dynamic address at first, and then log in remotely to change it to static. You can easily remote into a local PC, then access the Pi from there. For the few remaining cases where this is not an option, you can send somebody on site.

That was what I had thought about, this message from you confirms that I was on the right path.



Last 2 weeks , I set a Windows 10 SBC for a customer location which is really far from me (1200 km) and on initial settings my DHCP was set to keep same local IP to SBC mac@ . (everything was fine).

Two weeks after,I sent my SBC to the customer , once connected on customer's LAN, SBC got a new local IP and connected to cloud PBX (I didn't noticed IP was not the same as initial setup)

I added my phones , provisionned and then tried to call and each time i got "forbidden" it was impossible to use phones for outgoing calls.

After having factory resetted the phones, problem was already there and suddenly I thought about IP SBC, I saw it was not the same , so in Windows 10 I set NIC to static ip in network properties and got it back to initial IP set.
Then everything worked like a charm.

So for sure a fixed IP is the way to follow to avoid surprises like mine.

Thank you for sharing this experience with us, it is certainly very useful to understand that the IP must be static if we want everything to work well.



Can you not connect to a remote machine, and check out the network settings.

Even running advanced ip scanner should give you some clues on the network setup - 'https://www.advanced-ip-scanner.com/ and then you can get the pi a fixed IP address before shipping

Yes, it is a good idea, a bit cumbersome but it is feasible. The problem is that you want to disturb the customer as little as possible.
 
in my case I didn't have access to customer router config so my only solution was to set in Windows same IP i used in initial setup (of course I knew it was in same range as customer and IP I wanted to use was free)
 
  • Like
Reactions: Albert464
There is no perfect solution - as the answers indicate. However, we tend to use a DHCP reservation for this reason: eventually our clients hire new IT people or change internet providers or install a new router or decide VLANS are the way to go. In all of those cases, the subnet used for the phones is potentially changed. IF you are adept at arcane methods, you can potentially get to the isolated PI hanging out on an otherwise inaccessible subnet. However, doing this remotely is even more complex (yes - it is often possible). Despite all attempts, our clients never inform us of these changes until after the SBC has been abandoned on a tropical island with no suntan lotion and no cell coverage.
 
There is no perfect solution - as the answers indicate. However, we tend to use a DHCP reservation for this reason: eventually our clients hire new IT people or change internet providers or install a new router or decide VLANS are the way to go. In all of those cases, the subnet used for the phones is potentially changed. IF you are adept at arcane methods, you can potentially get to the isolated PI hanging out on an otherwise inaccessible subnet. However, doing this remotely is even more complex (yes - it is often possible). Despite all attempts, our clients never inform us of these changes until after the SBC has been abandoned on a tropical island with no suntan lotion and no cell coverage.
That's why we put in our contracts that if they change the network prior to warning us and it causes downtime, we bill to fix it. If they warn us before, we can do the necessary steps beforehand, so not billed. They tend to be more forthcoming after that.
 
  • Like
Reactions: DSXVOICE
There is no perfect solution - as the answers indicate. However, we tend to use a DHCP reservation for this reason: eventually our clients hire new IT people or change internet providers or install a new router or decide VLANS are the way to go. In all of those cases, the subnet used for the phones is potentially changed. IF you are adept at arcane methods, you can potentially get to the isolated PI hanging out on an otherwise inaccessible subnet. However, doing this remotely is even more complex (yes - it is often possible). Despite all attempts, our clients never inform us of these changes until after the SBC has been abandoned on a tropical island with no suntan lotion and no cell coverage.

Ok, so reserving the IP via MAC Address is the best way, so leave the SBC in DHCP for safety.

That's why we put in our contracts that if they change the network prior to warning us and it causes downtime, we bill to fix it. If they warn us before, we can do the necessary steps beforehand, so not billed. They tend to be more forthcoming after that.

Just hope that the new ISP will allow you to reserve IPs via MAC and that they will notify you before making these changes.
 
  • Like
Reactions: DSXVOICE
Just hope that the new ISP will allow you to reserve IPs via MAC and that they will notify you before making these changes.
If you can't do a simple DHCP reservation on an ISP router, just change the freaking router. Or don't install VoIP at all.

If it's an IT firm managing the network, they usually put good enough routers.
 
  • Like
Reactions: Albert464
I usualy keep a handful of addresses that are within the subnet but outside of the DHCP address pool.

Any decent router will allow you to set a DHCP reservation that is outside of the pool but still within the subnet. Alternatively, you can just keep a managed list of static IP's, again that sit outside of the pool but within the subnet.

Simple e.g.

Gateway 192.168.0.1
Subnet 255.255.255.0
IP addresses within subnet = 192.168.0.x
DHCP address pool 192.168.0.2-192.168.0.240

Leaves you 192.168.0.241-192.168.0.254 free to either allocate using DHCP reservation or statically (but you will obviously have to manage this range manually / properly!).
 
  • Like
Reactions: Evolute IT
I usualy keep a handful of addresses that are within the subnet but outside of the DHCP address pool.

Any decent router will allow you to set a DHCP reservation that is outside of the pool but still within the subnet. Alternatively, you can just keep a managed list of static IP's, again that sit outside of the pool but within the subnet.

Simple e.g.

Gateway 192.168.0.1
Subnet 255.255.255.0
IP addresses within subnet = 192.168.0.x
DHCP address pool 192.168.0.2-192.168.0.240

Leaves you 192.168.0.241-192.168.0.254 free to either allocate using DHCP reservation or statically (but you will obviously have to manage this range manually / properly!).

Ok, but if I reserve an address included in the DHCP pool via MAC, what you described would be just one more step, what benefits could it bring?
 
Ok, but if I reserve an address included in the DHCP pool via MAC, what you described would be just one more step, what benefits could it bring?

That you can guarantee that no devices are already sitting on the IP address you picked out in advance to use.

I'm a bit of a neat freak and like to keep all of my static IP devices (servers, SBC's, etc) together in a small sequential range. I'm not sure if that's good practice or just my obsessive nature but it sure makes remembering where everything is easier.

edit: I should explain that I meant I set the address pool once at the beginning of setting the LAN up to prepare for future devices, not every time I add a static device.
 
  • Like
Reactions: Evolute IT
SBC got a new local IP
For Windows 10 I have seen cases where the PC loses its static IP and reverts to DHCP. Usually when a feature update is installed (I suspect because it tries to install a new network driver and in the process loses the settings). It happened on most to all of such Win10 PCs several years ago...I want to say Win10 1607? But I saw it once this year upgrading client PCs to 20H2 (out of a couple hundred) and saw a post from someone else to which it happened. In those cases a DHCP reservation would reassign the same IP.

Any decent router will allow you to set a DHCP reservation that is outside of the pool but still within the subnet
FWIW, pfSense puts them outside the pool. Windows I think requires a reservation to be inside the pool? However it can be in an excluded range, which is how we do as you describe to have static IPs available. (pool .1-.254, exclude .200-.254)
 
can we have one SBC controller just hosted on google cloud etc or does each customer need to have their own SBC?
 
can we have one SBC controller just hosted on google cloud etc or does each customer need to have their own SBC?

1. Each customer has to have their own PBX

2. Each site the customer has, must have its own its own SBC locally installed (not in cloud)

Example

Company XYZ has 2 offices in 2 cities. They deploy one PBX in the cloud, then they install a SBC locally at office 1, and another SBC at office 2. Those two SBCs connect to the same PBX. It appears like all phones from both offices are on the same PBX.
 
1. Each customer has to have their own PBX

2. Each site the customer has, must have its own its own SBC locally installed (not in cloud)

Example

Company XYZ has 2 offices in 2 cities. They deploy one PBX in the cloud, then they install a SBC locally at office 1, and another SBC at office 2. Those two SBCs connect to the same PBX. It appears like all phones from both offices are on the same PBX.
Thank you John,

if no SBC we can set it up as direct connect?
i assume 3cx does not utilize edgemarks or devices such as that for SBC.

do you have a link or document for the SBC configuration best practice.
 
If no SBC installed, you can direct connect using STUN mode. We do not recommend this if the office has more than a couple of phones, and is usually less reliable than SBC.

We have a manual on how to deploy the SBC, but for best practices we generally advise the following points

1. Install the SBC on the same LAN segment as the phones
2. Give it a static IP!
3. Make sure you are not blocking outbound connections with destination port 5090 or 5001
 
Last edited:
  • Like
Reactions: Evolute IT
I have been installing zero tier vpn on sbc units sent out in case we need to remotely access them after a client updates something without notice. Very good option.

This means we can get remote ssh access to the raspberry pi units as long as it has Internet access. Usually it's a case of they upgraded Internet and isp drops in a new router or the isp tells them to factory reset the router as a troubleshooting step.

If its a normal isp router there is the default login info on a sticker on the router. we have the client read off the info (or text a picture of it), we can use ssh port forwarding to hit the router admin page and restore the dhcp reservation. We ask them to place a sticky note on router saying Attn: must reserve ip address for phone system mac xx:xx:xx:xx:xx:xx if router is replaced or reset. But I cannot recall if the note has ever saved it from happening.
 
Status
Not open for further replies.