Swapping out an old v11 system

Status
Not open for further replies.

techpowered

Forum User
Joined
Jul 18, 2019
Messages
3
Reaction score
0
We have an old 3cx v11 system on premise that hasn't been maintained well and has developed some issues. Instead of going through the various phased upgrades required to get to current, and since it is a pretty simple system, it seems like the best option would be to do a clean install. Reading through the requirements for the latest version, it seems there are some new requirements including new firewall rules and fqdm usage, etc.

We were planning on setting up a new win10 PC, installing the software and configuring it as much as possible in advance, then swapping it out with the old PC, reusing the old internal static IP and hostname and reusing the existing firewall rules, etc.

For those of you who have done multiple installs and/or upgrades, any issues with this approach? It's a pretty simple way to go, but I wanted to make sure we weren't going to run into any problems with the new setup process, etc. It sounds like the only thing I may need to watch for is starting out by telling 3cx I'm using a dynamic IP, so that it doesn't lock my license to the wrong external static IP while we're setting it up (off site).

Thanks in advance, any tips are appreciated.
 
I've never done it from that far back but the main concerns you will have are:
  • Features that may have been in present in v11 and are gone now (line in for MOH for example) or moved upstream from STD to PRO (queues, custom SMTP, etc)
  • Are your phone sets still compatible? Since it sounds like you are local LAN and staying this way it shouldn't be much of an issue.
  • Assuming they are still compatible the phones should probably be factory reset and re-provisioned given the jump. There's going be new firmware most likely, and definitely new templates. Also the provisioning path will have changed with the addition of the random folder.
  • The FQDN isn't going to be an issue if your phones are all local LAN provisioned since they won't use it typically
 
Thanks all for your advice so far...
  1. re: linux - I'm absolutely a fan myself and deal with more linux day-to-day than windows, but it's not an option for this deployment given the local (non-IT) people who need to maintain or "use" it day-to-day are barely windows-literate. :)
  2. About half the phones (yealink t2 series) are EOL but no advanced features are used, so they appear to be "ok" enough for now. The gigabit phones look fully supported. We'll update each phone as we remove it from the previous system and prep it for the new system.
  3. Our provider originally was cbeyond, which has been bought out a half dozen times by now, but appears still supported (fusion)
  4. Doesn't appear our license has been maintained or paid for some time, so we're assuming it's "useless" at this point and we'll need to start with a new one. I'm not sure who originally did the install or where they went. And unfortunately, we want/need to continue to have call recording, otherwise it looks like we might be able to get by with the "free" 8 SC license, so I'm assuming we'll run a trial and then decide between yearly licenses or one-time + maint. once everything is working well again. The licensing model does seem a bit odd and I can't quite figure out the advantages/disadvantages between the two options yet.
  5. No gateway at this time.

Side note, is v16 stable enough at this point?
 
Another side question regarding firewall/security, is it considered a best practice to block inbound SIP (5060) other than from the provider ranges if we're only using local LAN phones? When I stepped in to look at this system, I definitely noted a number of security concerns
 
It has been stable since March when it was released, and is receiving regular maintenance updates (currently on Update 2)

Port 5060 can be opened towards your provider range, if you have issues with connectivity you can adjust accordingly
 
Another side question regarding firewall/security, is it considered a best practice to block inbound SIP (5060) other than from the provider ranges if we're only using local LAN phones? When I stepped in to look at this system, I definitely noted a number of security concerns

One man's trash is another man's treasure... the same can be said for best practices. You could say that is the best practice until 6 months from now you forget you did that and spend hours troubleshooting remote phones, or your SIP provider adds another IP range, etc. But if it helps you sleep at night, go for it. 3CX is no different than any other application in your environment. Do whatever your normal security stance dictates, and 3CX takes care of the rest. There's really only two things to worry about; extensions being compromised resulting in toll fraud or DoS/crashing of the SIP stack. Sound 3CX defaults like complex extension passwords and country blocking, and now the global IP blacklist take care of the former, and 3CX historically has a pretty robust SIP stack and is designed to be internet-facing for the latter.
 
  • Like
Reactions: accentlogic
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,932
Messages
589,805
Members
164,804
Latest member
fcentral