WAN link Failover for Redundancy

Status
Not open for further replies.

SKDamon

Silver Partner
Advanced Certified
Joined
Aug 6, 2018
Messages
52
Reaction score
7
I'm having issues with my WAN failover...

3CX connects to the Internet via Firewall that has Uplink redundancy, being connected to 2 Uplinks.
There's a routing rule defined on the Firewall that routes all Traffic from local 3CX to Internet via WAN1,
if WAN1 goes offline all traffic from local 3CX to Internet is routed via WAN2.
3CX is configured as "Dynamic public IP" and STUN resolution works fine. PRO license.

Today, WAN1 failed and we successfully switched to WAN2.
Shortly after this, WAN1 uplink was restored and new connections were served via WAN1 again.
Except for the 3CX SIP registration.

Eventually, there was a mismatch of PublicIP detected via STUN by 3CX, and PublicIP used in SIP/SDP...
The result was no audio in outbound calls. Manually re-registering the Trunk solved the issue.
Before re-register, my VoIP provider showed WAN2_IP for the active registration, 3CX resolved its public IP to WAN1_IP.
After the re-register, both provider and 3CX resolved to WAN1_IP.

I guess the STUN resolution used WAN1 again after it was restored, since those are new connections every time.
The SIP registration was kept alive and never switched back to using WAN1.

So my question is: How should WAN failover be handled?
My provider only offers SIP via TCP/TLS, so switching to UDP is not an option.
Configuring a "hard" switch once WAN1 goes up again on the firewall is not desirable while WAN2 still serves connections.
The Re-Register Timeout is set to 600 (seconds?) in the SIP-Trunk settings, but the issue persisted way longer.

Should the 3CX Host be connected to both Uplink networks so it figures out its own failover?
SIP-ALG after all?
 
Configuring a "hard" switch once WAN1 goes up again on the firewall is not desirable while WAN2 still serves connections.
Though this would probably be the easiest way to solve this I can understand why you would want to avoid it. I'm not sure what capabilities the firewall you're utilizing has but is there any chance that, once a WAN failover occurs you then perhaps somehow maintain all traffic routing via WAN2 and only switch back to WAN1 if WAN2 fails?

If I understood the situation correctly I think configuring it in this way should solve the issue or at least improve the situation.
 
Hi Chris, thanks for your reply.

I think that might just be possible as a workaround. Though using the backup WAN until it fails is still not optimal, I can auto-reboot the WAN2 router at night to force a failover back to WAN1.

Other than that, I've always wondered about the message "Default best-route IP is determined as W.X.Y.Z" in the activity log. I've never tried nor read about support for multiple uplinks on the 3CX host itself.

Is it supported on 3CX Debian ISOs? Plugging our NUC into the WAN2 router directly via an additional NIC seems like an easy and cost-effective solution, no firewall failover required, given that 3CX can handle 2 default routes and failover?
 
What network configurations are supported by 3CX can he found here but I can't say if this particular setup is supported by 3CX per se as it has nothing to do with the immediate network config on the PBX. How the firewall is configured to route traffic does not matter to the PBX as long as it's done in a way that does not affect it of course such as making sure all 3CX's traffic is going out of only one IP.

Plugging our NUC into the WAN2 router directly via an additional NIC seems like an easy and cost-effective solution, no firewall failover required, given that 3CX can handle 2 default routes and failover?
We do support two NICs but only having a default gateway on one of them so I'm afraid this would not be the best way to do it.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru