SBC ports - real world

Status
Not open for further replies.

CRM250

Customer
Basic Certified
Joined
Dec 3, 2020
Messages
20
Reaction score
3
So thanks to @kieferschild for starting to explain this, allow me to explain the setup roughly.

Single site office - and a mixture of deskphones (not supported which is fine as they provision using the LAN IP direct to 3CX)
In this single site is a single 3CX server and possibly soon to be SBC
Reason for the SBC it to hopefully thwart the numerous attempts on port 5060 and reduce the surface area of attack on the main 3CX box.
Also this single site has just as many remote phones (mostly supported provisioned by STUN)

So by putting in a SBC and diverting port 5060 to look at this device instead should assist with the protection of 3CX
However do the remote phones all look at this for provisioning now ? do i need to re provision ?

As for putting the SBC on another network - i don't have one i care to use, there is another on a ADSL i could use, but pointing to that as the primary route for calls doesn't make sense.
Having a nearly hot spare 3XC on it is happening as that WAN IP is also on the gamma trunk.

We are talking a total of around 20 handsets here not hundreds.
As for desktop / mobile app, some do use these, but almost all the staff prefer to have a proper phone handset so this is the primary device by choice.
The tail won't be wagging the dog here.

Many thanks for any constructive and helpful advise guys
 
I think you're a little confused still. STUN devices cannot use the SBC in lieu of port 5060.

You provision a phone to use either STUN or the SBC.

The SBC is to be used at remote sites to create an encrypted tunnel from the remote site to the PBX.

The phones at the remote site behind the PBX will traverse via the SBC to the PBX mitigating the need to port forward to the remote phones behind the SBC.

There will always be attacks on every single open port you have and anyone else has on the internet. If you're going to use STUN then you will need to keep 5060 open.

As long as you're using the randomly generated passwords that 3CX creates and you have your anti-hacking set to the default values then you will more then likely have no trouble.

I have not restricted ports on my 3CX instances and in my cloud instances they're open to the world.

To this day I have not had a breach.
 
  • Like
Reactions: CRM250
Cheers for that.
If i manage to get a SBC installed i will check out the provisioning option.

Just battling with the debian image at the moment
 
  • Like
Reactions: CRM250
That is really helpful - first time i have seen that too.
Cheers
 
Status
Not open for further replies.

Forum statistics

Threads
111,988
Messages
590,158
Members
164,923
Latest member
2B_JPS