SBC Specs Query

Status
Not open for further replies.

thames

Customer
Basic Certified
Joined
Apr 4, 2011
Messages
175
Reaction score
12
Hi Folks

I'm about to supply a 42 seat 3CX system to a client. They have two buildings on one LAN with interconnecting routers and they have another building a little way away on a separate network with only two seats. The PBX will be hosted on a Google Compute Instance. I'm getting ready to figure it all out but would love some help with the "to SBC or not to SBC" question.

(a) Would you use an SBC standalone in one of the two buildings which are on the same LAN?
(b) Would you use STUN Remote for the two extensions in the disconnected building?
(c) Would you choose High Availability using two SBCs or just the one?

I usually use STUN Remote setup when I set up smaller 3CX systems but this is my first system with more than 15 extensions so really want to ensure I set it up correctly. If SBC is indeed the way to go, could someone please suggest the correct hardware to use for the SBC?

Many thanks in advance
Chris
 
Hi Chris,

You shouldn't need to. The router will do all this as long as the extensions are provisioned within 3CX as remote extensions (Direct SIP) they will be given the ports as you define in the extension setup for SIP/RTP, just make sure not to use the same ports for multiple devices sharing the same public IP, i.e. on the same network. No need to open inbound ports, the phone/router will agree all this behind the scenes. The rules they create are a held within the router (for a specific time called sessions) so depending on how many extensions you are trying to accommodate behind one router you may be putting to much demand on that routers memory, so will depend exactly which Draytek model you are using and can also be effected by other things/types of traffic that put demand on the routers limited resources.

In summary, if you are opening ports manually in the router config, you are doing it wrong :)

Dave.
 
You shouldn't need to. The router will do all this as long as the extensions are provisioned within 3CX as remote extensions (Direct SIP) they will be given the ports as you define in the extension setup for SIP/RTP, just make sure not to use the same ports for multiple devices sharing the same public IP, i.e. on the same network.

Ah - this is slowly filtering through this aged skull and agitating what's left of the grey matter! So as long as I have the extensions set up, each with different SIP port (5060, 5061, 5062 etc.) and each extension with its own RTP range (14000-14019, 14020-14039 etc.) I don't have to open any NAT or OPEN PORTS or PORT FORWARDING etc. on the router?

...so depending on how many extensions you are trying to accommodate behind one router you may be putting to much demand on that routers memory, so will depend exactly which Draytek model you are using...

OK I think I've got it. One of my clients has 11 desktop phones on a Draytek 2860n and everything appears to be working OK, although I have (stupidly now I have been told!) set up all kinds of port forwarding and each office phone has a static IP. I certainly won't do that again in a hurry.

I have this new client coming up, with 42 extensions including three Plantronics conference phones. They already have a Draytek 2830n router on site and I'm now wondering whether I should recommend they chuck it out and we put in a newer version (2860 or better if available).

In summary, if you are opening ports manually in the router config, you are doing it wrong :)

I'll get my hat and coat.... <shuffles off dejectedly> :D

@David Forster Thank you SO much - this post has cleared the cobwebs for me.... What was the name of that song... I can see clearly now? ;)

Cheers
Chris
 
  • Like
Reactions: accentlogic
ALSO, Take that Draytek, and throw it away, we used to use them, they are the most useless, underpowered pieces of junk for a firewall, with firmware that looks like it was developed by a low budget fly by night crew from the 80s.

The Draytek is actually harder to configure than a basic pfsense firewall for most of its functions.

Not to mention they recently had a security flaw that allowed anyone to hack into them with no effort at all, completely bypassing login.
 
ALSO, Take that Draytek, and throw it away, we used to use them, they are the most useless, underpowered pieces of junk for a firewall, with firmware that looks like it was developed by a low budget fly by night crew from the 80s.

The Draytek is actually harder to configure than a basic pfsense firewall for most of its functions.

Not to mention they recently had a security flaw that allowed anyone to hack into them with no effort at all, completely bypassing login.
@BrenttG I don't know the pfsense at all - is it a router/firewall like the Draytek?
 
Yes it is, and the user interface is 100x more friendly, configuring one for use at a site, including for 3CX to work with it, takes 5-10 minutes. and they support all the IPSEC, L2TP, vpn standards, have work from home vpns built in, and much more.
 
Draytek certainly has it's pros and cons, but does have a place in the market.

1) 2830's are EOL now so should be replaced as soon as possible

2) Always keep firmware up to date. There was an issue back in 2016 which was considered critical as BrenttG mentioned. To be fair to them this was the first one like this I remember in their history (and I've been using them a long time).

3) 2862 are the current flagship model and works well in a small business environment. If you do stick with Draytek for an office with 42 extension (and thus assume 42 PC's as well) I would seriously consider it's big brothers from the 29xx range or 3910 even. I'm guessing all those users are connected via a full fibre connection?

4) Save yourself lots of headaches, get some SBC's in there, you can even drop ship the hardware having preloaded all the MAC addresses into the system and they will 'just work' when first plugged in.

Dave.
 
2) Always keep firmware up to date. There was an issue back in 2016 which was considered critical as BrenttG mentioned. To be fair to them this was the first one like this I remember in their history (and I've been using them a long time).

Errr, and again in 2018

Errr, and again in 2020
https://www.zdnet.com/article/a-mys...sdropping-on-corporate-ftp-and-email-traffic/

https://thehackernews.com/2020/03/draytek-network-hacking.html
 
@BrenttG what model of pfsense would you recommend for my little installation of 42 extensions in office?
 
Interesting articles, and thanks for the correction re my date 2016, I was then referring to the 2018 issue.

I'm not saying they are perfect and it's worth putting these issues into context. Everything including Apple's iphone's have similar issues. Many of the problems can be mitigated by following best practices, i.e. not opening up router admin to the public network, keeping all routers/switches/ap's on separate VLAN's etc..

I just think it's worth considering all options based on both the project/budget/technical ability. Draytek.. buy it, plug it in and within 5 mins you're up and running, any problem ring Draytek or you supplier for support and exchange if necessary. pfSense you need to consider hardware it will run on, support options for hardware and software, etc..

I guess what I'm trying to say, in summary both solutions have there place.
 
https://www.amazon.com/Firewall-Micro-Appliance-Gigabit-AES-NI/dp/B0742Q3NT6/ref=sr_1_2?dchild=1&keywords=protectli&qid=1597645064&refinements=p_n_feature_four_browse-bin:2444556011&rnid=676578011&s=electronics&sr=1-2

We use these and they work miracles.

You just need to make a bootable USB to install to it, just accept all the defaults when you install pfsense.
The default install detects all the NICs, Drivers, Etc perfectly, even in the proper order, no need to mess with it.

Protectli is a US company, and stands behind their products 100%, we buy them in bulk directly from Protectli but for most people its easier to just get them on amazon. If you go to their website, you can order their devices with any needed international power adapter.

As a bonus, this same piece of hardware, or the 4 GB RAM version also work perfectly for 3CX SBCs, just burn the 3CX ISO, plug in a USB CDROM and install away.
 
Last edited:
  • Like
Reactions: David Forster
Just want to say a hearty THANK YOU to all who responded to my initial question. Things 3CX are a lot clearer now when it comes to the port forwarding (or not!) etc.

All the best
Chris
 
  • Haha
Reactions: David Forster
@thames

Here is the better link https://protectli.com/product/fw4a/

Select the power cord you need, and for a firewall or SBC i recommend, 4 GB RAM, 32 GB SSD

If you want to run 3CX on it as an actual PBX, go 8 GB and 128 GB SSD i recommend, or larger depending on recordings. You might also consider stepping up to a model with an Intel I3 or I5 CPU for larger 3CX Servers.
 
  • Like
Reactions: thames
OK I think I've got it. One of my clients has 11 desktop phones on a Draytek 2860n and everything appears to be working OK, although I have (stupidly now I have been told!) set up all kinds of port forwarding and each office phone has a static IP. I certainly won't do that again in a hurry.



Hi Chris,

Hope I'm not too late to the party but I should insert a main clarification here:

Even though there are some firewalls that can indeed very reliably handle STUN phones properly without setting up port forwards for each phone, I'm sure you've realized over the years that not every manufacturer will implement things the same way.

This introduces an unknown variable, since the STUN phones can be deployed behind a variety of firewall/router manufacturers, with a variety of models and board revisions, and a variety of firmware editions, behind a variety of network conditions - factors that an admin cannot always control but needs to be flexible to handle.

Given that the above creates a chaotic mess, we always recommend that the ports of STUN phones be forwarded, and this acts an insurance policy against any behavior any specific firewall/router may have that you will have the joy of discovering when the customer calls you up and says that their phones aren't working. When contacting 3CX Support with STUN phones facing issues we will need you to make sure that those forwards are in place, and that the issue can be replicated with these conditions before moving forwards.

An SBC of course makes this a non-issue and this is why we recommend using it when deploying more than a handful of STUN devices per site, to make your life easier and reduce the amount of administration needed.

Given what you know now forwarding the ports on the DrayTek was not a bad idea ;)
 
Given what you know now forwarding the ports on the DrayTek was not a bad idea ;)

There you go, that's me put in my place :)

But I can confirm that in what I would call a 'proper setup', i.e. the router has a fixed public (accessible and not shared) IP address with no other technology interfering with the transmission upstream then every model of Draytek will play nicely.

That all said, as John has pointed out and as per my original posting. Just save the headache and pop some SBC's on site.

Dave.
 
This introduces an unknown variable, since the STUN phones can be deployed behind a variety of firewall/router manufacturers, with a variety of models and board revisions, and a variety of firmware editions, behind a variety of network conditions - factors that an admin cannot always control but needs to be flexible to handle.

Given that the above creates a chaotic mess, we always recommend that the ports of STUN phones be forwarded, and this acts an insurance policy against any behavior any specific firewall/router may have that you will have the joy of discovering when the customer calls you up and says that their phones aren't working.

STUN or more accurately direct SIP is partially problematic for 3CX because by default SIP signaling is run over plain-text connection-less UDP. This allows for all sorts of MITM interference. If 3CX would make an effort to support standard encrypted SIP TLS over connection-oriented TCP for popular desk phones half of these issues would go away.

If a router is not properly handling NAT it tends to be immediately obvious. One way audio, no audio, or failure to register once a second phone is added are all red flags.

Incoming ports should never be opened to anything unless absolutely necessary, especially client devices as they tend to be high risk attack vectors. Proactively opening ports without good justification is poor SecOps.
 
  • Like
Reactions: David Forster
indeed. I have found a lot of the time that just forcing TCP for the SIP Ports(not RTP) solves a good portion of the problems as far as desk phones to the Cloud Based PBX. And without the need of using TLS, obviously TLS is more secure, but if your on a reputable ISP i isn't quite as big an issue.

The other problem is some providers have UDP filtering, and block a lot of ports on UDP completely, we have found some of these ISPs the hard way, usually if we find an ISP doing it, they claim its in the name of security, or anti-ddos, or some other nonsense, but its always laziness on their part to just blanket block UDP across the network only allowing UDP for DNS and PING rather than actually have staff that know how to block DDoS traffic on a per incident basis.

Its usually those same ISPs that also block large pings for the same reasons, which prevent you from using large packet size pings to test for jitter and packet loss.
 
  • Like
Reactions: David Forster
Hi there

Again, thanks to all who have responded. You have made things a lot clearer for me. Here's hoping the next install (42 extensions no SBC) will work OK.

Another question, related to my original question here...

I have a remote user with a Fanvil X6U phone and I cannot get it work on the new Draytek router we installed on his broadband line. I have checked that ALG is not enabled. I have the PBX set for his extension to provide the RTP and I have the "legacy" box checked as well.

Simply cannot get audio to work on the Draytek for this extension. At their head office I have an identical Draytek set up and 12 extensions, all working 100%.

Now the confusing bit... this guy also has a Virgin cable modem in the office. It has never been touched for VoIP and is bog standard. However, if he plugs the Fanvil into the Virgin box, it works instantly.

I guess that means that there is some issue with the Draytek. I have looked and cannot see anything untoward in the setup. Just before I get my customer to throw it out in the rain, does anyone have a clue what could be causing the issue?

All the best
Chris
 
Hi Chris,

Not necessarily, the Virgin ISP box may be blocking SIP after the DrayTek.
Try assigning a different SIP port to the phone and see if this helps.

Also see if the ISP box can work in bridge mode or at least DMZ so that the DrayTek has full access to the internet.
 
  • Like
Reactions: David Forster
I agree with John.

Just to clarify, the Draytek is plugged into the Virgin box? If that's the case then Double NAT will probably be at play.

I've not found DMZ's to be very helpful at solving such an issue (not on Draytek's anyway) they get confused at reporting their public IP address and actually use the local IP address the Virgin router has passed onto them.

Bridge mode is your best bet, but ironically Virgin only offer this on a service with a dynamic (non fixed IP) which is a little annoying if you happen to be paying the extra for a fixed IP. On related forums it's a well requested feature for Virgin to sort.

I have provisioned a service on exactly the same setup earlier this month, Bridge mode wasn't available, so used DMZ (just so I could remote configure Draytek if needs be at any point) and then a little SBC (have I mentioned I'm a fan of them).

Dave.
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur