- Joined
- Jun 2, 2014
- Messages
- 5,571
- Reaction score
- 1,981
I'll slightly disagree here and I'll explain why.Are there any plans to include tunnel mode? this is a major backwards step in terms of security and limiting firewall policies to a single encrypted port which was the whole point of tunnel mode.
For remote users this is a huge backwards step
In order for a 3CX Client to work it for sure requires access to the HTTPS port for the Presence information. This also applied for the legacy Windows App, so there is no change here.
Now the 9000-10999 port ranges are the audio ports used by 3CX for SIP Trunks as well, so we can say with a fair certainty that on most 3CX systems there are open as well. There is no real danger of leaving these ports open to all IPs on your Firewall, because nobody can use them to abuse your system, and 3CX does have protection against RTP injection.
Talking about encrpytion, the new Desktop App, as the WebClient, uses WebRTC, which uses a TLS connection for signalling (to HTTPS port) and DTLS for the Audio transmission (to/from ports 9000-10999) which is also encrypted.
I'm not seeing the step back...