SBC Specs Query

Status
Not open for further replies.

thames

Customer
Basic Certified
Joined
Apr 4, 2011
Messages
175
Reaction score
12
Hi Folks

I'm about to supply a 42 seat 3CX system to a client. They have two buildings on one LAN with interconnecting routers and they have another building a little way away on a separate network with only two seats. The PBX will be hosted on a Google Compute Instance. I'm getting ready to figure it all out but would love some help with the "to SBC or not to SBC" question.

(a) Would you use an SBC standalone in one of the two buildings which are on the same LAN?
(b) Would you use STUN Remote for the two extensions in the disconnected building?
(c) Would you choose High Availability using two SBCs or just the one?

I usually use STUN Remote setup when I set up smaller 3CX systems but this is my first system with more than 15 extensions so really want to ensure I set it up correctly. If SBC is indeed the way to go, could someone please suggest the correct hardware to use for the SBC?

Many thanks in advance
Chris
 
An SBC would keep extension to extension traffic within the LAN and secure tunnel PSTN traffic back to the PBX.

I come from the land of Asterisk and generally prefer the PBX to handle everything. An SBC at a remote site is yet another moving part that can break, even with HA. In my opinion, an SBC is useful only when the latency to the PBX exceeds 100ms or connectivity to the PBX is prone to packet loss.

A nice thing about "STUN Remote" is that if someone needs to move a phone home or to another office it'll just work. No need to get IT involved.

The drawback with "STUN Remote" is that by default signaling and media are sent in the clear over the public internet. One can use TLS/SRTP to avoid this but 3CX requires one to use custom phone templates:
https://www.3cx.com/community/threa...4x-sip-over-tls-srtp-using-remote-stun.74747/
 
Thanks both @Itctech and @SteveITS for yor responses. The last system I put in had 12 local extensions and a couple of remote extensions, all with desk phones. I set them all up using STUN remote and the whole thing works perfectly.

With 40+ desk phones there will be 40+ BLFs on each phone. I assume this means I should possibly use STUN Remote set up rather than SBC? As long as STUN will work with this many extensions, I'd be much happier to go for STUN.

So the next question... for the extensions on the local LAN (40 of them) do I need to give them all static IP addresses and then do port forwarding of the range of SIP ports and RTP ports or do I really not have to bother with that?

All the best and thanks again
Chris
 
for the extensions on the local LAN (40 of them) do I need to give them all static IP addresses and then do port forwarding of the range of SIP ports and RTP ports or do I really not have to bother with that?

As long as the router on site is using dynamic outbound NAT none of this should be necessary. And if it is necessary, the router needs to be reconfigured and if that's not possible replaced.
 
As long as the router on site is using dynamic outbound NAT
Thanks, @ltctech.
I'll go check the dynamic outbound NAT capability of the router. I'd feel much better removing the SBC from the equation.
 
Hi Chris,

Just to put the cat among the pigeons so to speak, I'm a fan of the SBC's. I mainly use PI 3B+ and if the numbers of extensions/blf's demand it I just add a few of them. I tend to put them into sites that have 2 or more extensions. Why? Well firstly now that you can see SBC status in the trunk section it's yet another fault finding tool, i.e. you can check it's up and how long it's been up for. I also like the fact I can drop ship a new hardware device to site and as long as someone onsite is capable of opening a box and plugging a phone into a network port the rest can be done from the 3cx control panel. And of course it just removes the uncertainty of the router/configuration, unless you have supplied that of course.

Dave.
 
  • Like
Reactions: accentlogic
Hi Dave
I have some time before this installation goes in, so I might just check out the PI 3B+, install it on our own 3CX network to get a feel for how things have changed.
All the best
Chris
 
  • Like
Reactions: David Forster
Hi Dave
I have some time before this installation goes in, so I might just check out the PI 3B+, install it on our own 3CX network to get a feel for how things have changed.
All the best
Chris

The great thing about the PI is there are no moving parts, no fan to break etc.

There are some really nice metal cases available that act as a heat sync and with the help of a local sign company you can even add a bit of branding as well for a few pence per device.

Annotation 2020-08-15 111223.jpg
 
As long as the router on site is using dynamic outbound NAT none of this should be necessary. And if it is necessary, the router needs to be reconfigured and if that's not possible replaced.
@Itctech what routers would you recommend that handle the dynamic outbound NAT?
 
@Itctech what routers would you recommend that handle the dynamic outbound NAT?
I guess it depends on the overall throughput of the router (assuming you are using it for data as well as voice), but I've always found Draytek routers to play nicely with 3CX. They are also easy to configure to reserve bandwidth just for your connections back to the cloud PBX.
 
Another vote for the SBC route. Yes, as @ltctech mentioned, it adds another point of failure, but we feel the advantages outweigh the risk on larger installs. You get to use default templates with plug-n-play provisioning and get encrypted connections back to the PBX.

The cluster SBC setup is still in beta, so for this one we would install one Intel NUC i3 unit at each building, and use STUN at the two phone site. Use a Voice VLAN with QoS, and balance the phones between the two SBC units so if one does go down both buildings still have half the phones working. These will be strong enough that you can convert to the cluster setup when it rolls out - but I'd recommend keeping BLF keys down to what is really needed, and not setup a BLF for every extension on every phone.

Another advantage to the SBC is you can install a remote access tool so that you can remotely login to phones or do other troubleshooting. We also run smokeping on them to monitor internet connections. If you do this be sure to let the client know - it is one reason we put them on a VLAN, mostly on installs where another vendor handles IT so we can maintain proper separation.
 
  • Like
Reactions: thames
There are some really nice metal cases available that act as a heat sync
Hi David
could it be possible to share where you buy and which case model you use , I'm impressed by nice design.
what is the cost for brand sticker? do you produce yourself or another company do it for you?

To stay in conversation I'm a SBC man too.
 
For the use case you have mentioned, i would recommend the SBC Route, but rather than doing it on a PI, i would recommend something a little more robust that is also designed for this type of purpose.

https://www.amazon.com/Firewall-Micro-Appliance-Gigabit-AES-NI/dp/B0742Q3NT6/ref=sr_1_2?dchild=1&keywords=protectli&qid=1597645064&refinements=p_n_feature_four_browse-bin:2444556011&rnid=676578011&s=electronics&sr=1-2

We have those devices in use handling 50-100 phones without issue, and you simply plug in a USB CD/DVD drive and install the 3CX SBC right off the 3CX ISO. no need to mess with GUI, the PIs power settings, etc, and the entire case is the heatsink as it is all aluminum, no fans needed, and they are built solid as a brick. The SSD and RAM are already in it, it is ready to boot to a CD or Flash Drive and install when it arrives. If you go to the protectli website you can order them with a large variety of configurations, and various international power cords, just avoid the Celeron models, for SBCs any of the Atom models are very cheap and perform flawlessly with large numbers.

They also work perfectly with pfSense if you need a highly customization and powerful firewall capable of gigabit speeds. We presently have almost 200 of these units deployed, as either firewalls, 3CX SBCs, and in a few cases 3CX itself is actually running on them as a small on-premise server, extremely robust and reliable, easy to setup.
 
Hi David
could it be possible to share where you buy and which case model you use , I'm impressed by nice design.
what is the cost for brand sticker? do you produce yourself or another company do it for you?

To stay in conversation I'm a SBC man too.

Hi, here is the link to the case we use. You should be able to build a PI 3B+ inc power supply, memory card etc. for about £65, so it's the budget option, but for installs with 20 or less extensions I find them reliable and great value of money (I know specs say 50 ext's for a PI but I like to leave plenty of headroom). I know others like to use much higher spec units (and higher priced), but I think more smaller units means if something does go wrong it won't knock out every extension. If it's a bigger site and they have their own IT you could also talk to them about some VM's on their in house servers.

Case link - https://thepihut.com/collections/raspberry-pi-cases/products/flirc-raspberry-pi-3-b-case

As for stickers, So they were printed onto vinyl and cut out by a local sign company. I ordered about 50 of them so worked out £0.50 each from memory. (I supplied artwork).

Dave.
 
@David Forster , thanks for detailled answer, is it possible for you to share with me, the file design you've done with or without your company infos.
 
@David Forster , thanks for detailled answer, is it possible for you to share with me, the file design you've done with or without your company infos.
I'll check with our designers and the sign company, see who still has the file and forward on. :-)
 
  • Love
Reactions: AWS2P
Another thing to watch out for on routers is SIP rewrite or Application Layer Gateway (ALG). They're all evil. STUN Remote is vulnerable to them as by default SIP signaling is transmitted in clear-text. The router can easily mangle clear-text traffic thinking it knows better. The solution is industry standard encrypted SIP; SIPS, SIP over TLS.

An SBC uses a proprietary encrypted tunnel to counteract the router, one doesn't need to understand all the gotchas of VOIP, and thus they're simpler to deploy.

@Itctech what routers would you recommend that handle the dynamic outbound NAT?

I'm a fan of pfSense but it has its advantages and drawbacks.

TBH, most properly configured routers already do this. There is no standard name for it and some implementations differ, some call it "Symmetric NAT", "NAT overload", or "Port Address Translation" (PAT).

It's the process of translating a given source LAN IP : port to a source WAN IP : port, where the source WAN port chosen by the router is random for each destination IP : port. The translation is kept in a router state table with an idle timeout. This has a few implications:
  • This punches a hole through the firewall that allows the destination to send packets back too.
  • Nobody but the destination can send packets back to this port.
  • This avoids port collisions when multiple LAN devices use the same source ports.
In practice, if you're having to manually configure unique source ports on any kind of client (servers are different), then either chuck the router or the sysadmin that configured it. :P
 
  • Like
Reactions: David Forster
TBH, most properly configured routers already do this. There is no standard name for it and some implementations differ, some call it "Symmetric NAT", "NAT overload", or "Port Address Translation" (PAT).

It's the process of translating a given source LAN IP : port to a source WAN IP : port, where the source WAN port chosen by the router is random for each destination IP : port. The translation is kept in a router state table with an idle timeout. This has a few implications:
  • This punches a hole through the firewall that allows the destination to send packets back too.
  • Nobody but the destination can send packets back to this port.
  • This avoids port collisions when multiple LAN devices use the same source ports.
In practice, if you're having to manually configure unique source ports on any kind of client (servers are different), then either chuck the router or the sysadmin that configured it. :p

THANK YOU!!! I try to explain this to people all the time, in pfsense this is literally a checkbox, bang, DONE! SonicWALL its a flip switch, as long as your firmware is from the last two years or so, mind you i hate sonicwall with a passion.

For 3CX purposes, pfSense is in my opinion the single easiest and most reliable firewall to use, be that in remote sites, or as a firewall to put a cloud/hosted 3CX server behind, because it keeps all the ports proper and mapped correctly, even with hundreds of phones, and many ips, as long as its configured properly. If it didn't work right for you, you didn't configure it properly.
 
  • Like
Reactions: David Forster
For 3CX purposes, pfSense is in my opinion the single easiest and most reliable firewall to use, be that in remote sites, or as a firewall to put a cloud/hosted 3CX server behind, because it keeps all the ports proper and mapped correctly, even with hundreds of phones, and many ips, as long as its configured properly. If it didn't work right for you, you didn't configure it properly.

This is something I've been wondering for a very long time.... so please be patient while I understand what we're saying...

Let's say we have a 3CX installation on a computing instance in the Google cloud. 3CX installs perfectly and the PBC firewall checks out 100% no problems.

On the site where the phones are, there is a Draytek router which does what Draytek calls "port forwarding" and "port redirection" (two separate functions) both of which require for the port or range of ports to be forwarded to specific IP addresses.

So my question is... If we want to use DHCP for the phones so they can be effectively used anywhere, how on earth do we set up the "dynamic outbound NAT" so that we don't have to put each of the SIP ports for each phone and the RTP port range for each phone into the router.

I've been in the industry for 30 years but when it comes to 3CX I'm completely confused by this.. Any help would be so gratefully accepted.

Many thanks - please don't chuck out this network engineer! ;)
Chris
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur