SBC and Firewall

Status
Not open for further replies.

Albert464

Customer
Intermediate Cert.
Joined
Oct 21, 2017
Messages
110
Reaction score
9
Hi, my company uses 5 STUN phones, we are installing a firewall so I would like to insert an SBC (Raspberry Pi 4) to be able to work better without problems.

Currently our 3cx PBX is in the cloud on google.

What ports do I need to unblock on the firewall for SBC to work?
 
Hey @Albert464

If you are talking about the firewall on the 3CX SBC end (between the 3CX SBC and the internet) then you need not forward any ports. The 3CX SBC will perform outbound connections to the tunnel port of the 3CX PBX (default TCP and UDP 5090) and the 3CX PBXs HTTPS port (default TCP 5001 or 443), that said, if you are not restricting any outbound traffic on the 3CX SBC end and the mentioned ports have been forwarded on the 3CX PBX end, you should be fine.

Do remember to factory reset the devices and then reprovision them using the 3CX SBC method.
 
Hey @Albert464

If you are talking about the firewall on the 3CX SBC end (between the 3CX SBC and the internet) then you need not forward any ports. The 3CX SBC will perform outbound connections to the tunnel port of the 3CX PBX (default TCP and UDP 5090) and the 3CX PBXs HTTPS port (default TCP 5001 or 443), that said, if you are not restricting any outbound traffic on the 3CX SBC end and the mentioned ports have been forwarded on the 3CX PBX end, you should be fine.

Do remember to factory reset the devices and then reprovision them using the 3CX SBC method.

The cloud PBX on Google has no Firewall limitations, all ports are open.
So if I don't get it wrong, I just need to connect the SBC to the Firewall and it will automatically connect to the PBX server, without having to open ports on my Watchguard Firewall in the company. Correct?
 
Yes, if you do not have any outbound restrictions you should not have any issue.
 
  • Like
Reactions: ChrisC_3CX
I am just curious : all ports open on a cloud machine ? I don't use cloud a lot but isn't this a security issue ?
 
I am just curious : all ports open on a cloud machine ? I don't use cloud a lot but isn't this a security issue ?
The ports that need to be opened, regardless where 3CX is, are these:
https://www.3cx.com/docs/ports/

3CX does an excellent job and protecting the services running on these ports, so yes the odds are you will eventually get 'attacked', but if you haven't changed the default security settings (randomly generated password SIP, MC log in credentials, etc), then you should be fine.

You can check out the security measures 3CX has here to better understand how 3CX protects you:
https://www.3cx.com/3cxacademy/videos/advanced/security-with-3cx-phone-system/
 
I am just curious : all ports open on a cloud machine ? I don't use cloud a lot but isn't this a security issue ?
In theory yes, in practice...maybe? If you aren't running anything on the 3CX instance other than 3CX. then the only open ports are the ones that would be open anyways so..
 
Status
Not open for further replies.