SFTP to Azure Blob Storage

Status
Not open for further replies.

johnporteous

Premier Customer
Advanced Certified
Joined
Sep 29, 2022
Messages
58
Reaction score
9
Hi All,
I've created a storage account on our Azure (and used Gen 2 Lake storage as recommended by MS) and setup SFTP for Recordings Archiving. I get passed the authentication on 3CX when adding all my settings (and I did have to try several permutations), and I even changed the SSH password on Azure to make sure it was reaching the container. I then setup up a test archiving job, and I get no errors anywhere that I can see.
I got onto MS and they gave me a long list of clients that will work with Blobs.
So I guess I have 3 questions please, if anyone is able to assist:
1. What is the built in SFTP client on Debian that is used for this - at least I can then tell MS and they can deny responsibility :-)
2. Where can I find details of what's happening on the connection and authentication from 3CX to the Blob?
3. Has anyone successfully managed to use this route to archive call recordings, because I'm damned if I can work it out? LOL

Many thanks in advance, any guidance would be gratefully received.
John
 
I am not super familiar with Azure but here are my thoughts.

1. Maybe a 3CX Engineer can answer you more specifically, but you can see the software/dependencies used under MGMT Console > Settings > License > "Credits" in the top right (https://FQDN:5001/#/app/settings/licenses)

I know FluentFTP is used for Backups, not sure about Archiving Recordings.

2. Can you run a packet capture of the traffic when you manually export? (tshark or ngrep?) It will likely be encrypted but you at least you know an attempt is being made.

3. We have several different customers using our "S3 to SFTP Connector" for Google Cloud Storage/Azure Blob/AWS S3/Digital Ocean Buckets(S3) to offload recordings.

Is port 22 open in firewall? Are the permissions correct in Azure? Does it have permissions to create folders? (Each Extensions recordings go in their own folder named after the extension ie. 1001 IIRC) Have you restarted 3CX Services since adding the Archiving Job?

I assume you have followed all the steps here: https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support-how-to (Looks like this is considered "Preview" and not finalized.)

I am not sure if Azure Blob Storage is using the S3 Protocol but something to note is, S3 does GET, PUT, and DELETE, no renaming of files (in my limited experience).

I hope this helps, let us know what you find out!
 
Hi Nathan,

Many thanks for your detailed reply. I have submitted a ticket with MS, but judging by the response thus far I'm not holding my breath.

Unfortunately we are not supported for 3CX assistance at this stage, hence me trying this avenue.

I've followed their instructions and it's all setup correctly on the Azure side. On the 3CX side I'm 99.9% sure it's setup correctly (as per MS guidelines) as I configured it with either just SSH password and also with SSH Password and OpenSSH key, and both were accepted by the PBX. I then changed the passwords and the authentication check failed on 3CX to Azure, so that does tell me it's hitting the storage at least.

Yes Port 22 is open and the permissions on the storage container in Azure is set to All so no issues creating a folder etc. And finally the services have been restarted since this was configured.

I'll run a traffic capture and hopefully get confirmation that 3CX is reaching it's target, at least I can then tell MS it is most likely their side.

Kind regards
John
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet