Webclient and SBC

Status
Not open for further replies.

siscom

Customer
Basic Certified
Joined
Jul 14, 2009
Messages
237
Reaction score
37
Good Afternoon Colleagues
I hope you are doing well , What i understand that 3CX SBC used to allow Hard Phones and Soft Phones installed on windows PC to connect to 3CX server at remote side bypassing firewall and NAT restrictions.

Can i use SBC to do the same with Webclient /3CX Desktop application ?

Best Regards
 
The webclient / desktop apps have the SBC (ok, tunnel) built into them so no separate SBC is needed.
 
  • Like
Reactions: GregG_3CX
Hello SweetAction
Thx for your replay . What i understand that for webclient / desktop apps to work correctly (hear two audio when using them) , We need to port forward ports 9000-10999 (inbound, UDP) for RTP (Audio) communications at 3CX side . If tunnel used , Only port 5090 TCP/UDP is required.

SO kindly advice.

Best Regards
 
Hello SweetAction
Thx for your replay . What i understand that for webclient / desktop apps to work correctly (hear two audio when using them) , We need to port forward ports 9000-10999 (inbound, UDP) for RTP (Audio) communications at 3CX side . If tunnel used , Only port 5090 TCP/UDP is required.

SO kindly advice.

Best Regards
Technically the webapp/desktop client uses secure websockets instead of the tunnel, but it has the same result - handle NAT/Firewall issues. There is no official way to change them to use the tunnel specifically. Only the legacy v16 desktop app and mobile apps use the tunnel on 5090.

9000-10999 is ALSO needed to handle RTP from a SIP Trunk to 3CX, although if you are doing audio without a SIP Trunk, I guess you can avoid that requirement.
 
  • Like
Reactions: GregG_3CX
@siscom The remote site does not need any ports forwarded. If you are concerned about allowing ports 9000-10999 on the server's end, and you know the remote office's IP address, you can limit access to that IP (and the SIP provider's IPs, as noted above). However an employee can't just log in to the web client from home in that case.

Hardware phones or ATA devices need an SBC or router phone. None of the 3CX software uses an SBC.
 
Technically the webapp/desktop client uses secure websockets instead of the tunnel, but it has the same result - handle NAT/Firewall issues. There is no official way to change them to use the tunnel specifically. Only the legacy v16 desktop app and mobile apps use the tunnel on 5090.

9000-10999 is ALSO needed to handle RTP from a SIP Trunk to 3CX, although if you are doing audio without a SIP Trunk, I guess you can avoid that requirement.
Thx for your replay
 
@siscom The remote site does not need any ports forwarded. If you are concerned about allowing ports 9000-10999 on the server's end, and you know the remote office's IP address, you can limit access to that IP (and the SIP provider's IPs, as noted above). However an employee can't just log in to the web client from home in that case.

Hardware phones or ATA devices need an SBC or router phone. None of the 3CX software uses an SBC.
Good Afternoon SteveITS
How can i limit access to remote office's IP address ?

Best Regards
 
How can i limit access to remote office's IP address
This would be done in your firewall that is in front of 3CX.
 
Thx for your replay SteveITS
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet