Solved V20 and DNS Split

Status
Not open for further replies.

jaredmedcomp

Premier Customer
Joined
Aug 5, 2020
Messages
3
Reaction score
1
Hi

I hope someone can assist me.

I have recently upgrade our 3CX to V20. Followed all the steps as provided by 3CX to the point. Everything went well but our SSL is showing as insecure. I have then learned with a on premis solution I have to do DNS splitting. I have then come across the DNS split that needs to be configured. I found the following step by step setup on the 3CX site (https://www.3cx.com/docs/pfsense-firewall) which I also followed as instructed but still no joy. We are making use of a pfSense firewall.

Can someone assist please by telling me what I am missing?

Thank you...
 
If you have an internal DNS server, then there is no configuration necessary for internal connections on your firewall. Just resolve your FQDN internally from the internal DNS server.

You would need to use your firewall if you do not have internal DNS services in your network.

For the PFsense, see this link which takes you directly to the configuration of the hairpin NAT https://www.3cx.com/docs/pfsense-firewall/#h.qcjy6w4vfhbg

This is step 3, option 2

1731941729213.png
 
What is doing DNS in your network? Is the pbx secure when you try from the outside of your network? I am not sure what your certificate with split dns have in common. Do you use some proxy for in front of your pbx?
 
I assume since we are talking about Split DNS, that your 3CX server is on-prem. If that is the case, the simple test is as follows:

1. From a PC on your internal network, ping the FQDN and take note of the IP address the FQDN resolves to on your PC. It should be your internal private IP address on your 3CX server.

2. From a PC outside your network (a home PC for example), ping the FQDN of your 3CX server. It should resolve to your public IP address.

If both 1 and 2 resolve to different addresses, and the addresses are correct, then you have setup Split DNS correctly. If you get the same IP address both inside and outside, then you have not setup Split DNS correctly.

If when pinging from a local PC you do not get the correct address, it is possible that your PC has cached your old pre-split IP. On your Windows PC, open an elevated command window and enter the following command:

ipconfig -flushdns

This will clear your cache on your local PC. Then try pinging your FQDN again to see if you get the correct IP. If you still do not get the correct IP address, then you do not have Split-DNS configured successfully.

But let's backup for a minute. It sounds like the URL you are using may resolve to a valid IP address, but does the certificate FQDN match what you are typing in your browser? For example, if you browse to https://192.168.1.20:5001 that is not using your FQDN and the certificate will not match what you are typing in your browser. You can have your browser display the certificate you are using. Make sure the FQDN you are entering in your browser matches exactly your certificate FQDN.
 
Hi Guys
Thank you for all the replies.
@VoIPTools when I ping locally for in and out of the network I get different IP's but not the local IP at all. Our 3CX is linked to a virtual static IP which is configured in the pfSense firewall. We have 5 static IP's. On local it resolves to the primary IP but from outside it is the correct public IP. I think that is my problem. How do I get the local side to resolve to the Local IP?
What am I then missing?
 
If your PFsense is your DNS than you just have to follow the manual.
 
Hi Guys

Thank you very much for all the responses.

I came right. Setting on our pfSense was missed.
Sorted
 
  • Like
Reactions: bitn2
Status
Not open for further replies.

Forum statistics

Threads
111,956
Messages
589,928
Members
164,861
Latest member
LewisJC