If you can't do DNS changes on a DNS server you'll have to manually edit the host file on each PC to handle this.I have the issue where I am using a Ubiquiti Dream Machine. The firewall checker is fine. I have all my ports in the forwarding of it. It is not a DNS server so I see no way of doing a split DNS or haipin nat. So now what? I'm testing this on my system before rolling it out to customers.
And what if you are self-hosted but are not running a DNS server? I have the UDM pro and it supposed to automatically do that hairpin nat from what I understand, but it is not working and I see now way of putting one it. I have multiple customers in this configuration that if there is no work around I will not be able to upgrade them to v20.See the text of https://www.3cx.com/community/threads/post-in-relevant-category.115838/
Also if self hosted see https://www.3cx.com/docs/creating-fqdn-split-dns/
Thank you, I forgot all about the local host file. But yes, this adds a layer I was not expecting and will be difficult as some customers do some administering themselves of the system. So if I understand this correctly, all users getting into their web interface even for their extensions will have this issue correct. That is going to be very problematic. I won't have a choice to either move them to the cloud, or to install a DNS server.If you can't do DNS changes on a DNS server you'll have to manually edit the host file on each PC to handle this.
Or consider hosting it in the cloud. If you don't have the ability to handle DNS onsite (or turn on hairpin nat), what other issues will you run into?
I'm confused and hoping you can help me here.Thank you, I forgot all about the local host file. But yes, this adds a layer I was not expecting and will be difficult as some customers do some administering themselves of the system. So if I understand this correctly, all users getting into their web interface even for their extensions will have this issue correct. That is going to be very problematic. I won't have a choice to either move them to the cloud, or to install a DNS server.
Thank you for all the information. I tried everything to the detail of what you suggested and it does show that it's resolving. Then I was having HSTS issues. Cleared that, and now it's back to where it was acting like it's not resolving although it resolves in nslookup.@pbpunisher your Unifi Dream Machines (UDM) has a DNS server built-in. Though much of the confusion revolves around how Unifi implements and lets you manage DNS.
1) Make sure you have your DHCP server set to point DNS traffic to your UDM. Under Networks > typically your "Default" Network > DHCP Service Management > Show Options > set the DNS server to the LAN IP address of your Dream Machine.
2) Under "Client Devices" > locate your local 3CX server > open it and go to Settings (top right) > tick the box for local DNS record and type in the FQDN of your 3CX server (i.e. "yourcompany.3cx.us" of whatever your FQDN is).
Make sure your client devices get the new DNS server from DHCP > ipconfig /release && ipconfig /renew > ipconfig /all to check DNS Server and make sure it's pointing to your UDM's IP address.
nslookup > type in your 3CX FQDN and het enter and if everything is configured correctly you should get back the local network address of your 3CX server.
This is called "Split DNS" clients inside your LAN get the local LAN IP address of the 3CX server while clients outside the network get the public address of your UDM which you would need to setup Port Forwarding for all the external traffic.
EDIT: Also to make it easier you can also setup DoH or "DNS Shield" under Settings > Security > General > set "DNS Shield" to "Auto." This will setup DNS over HTTPS (DoH) to forward to CloudFlare and Google DoH Servers. Then once again make sure you setup your Default LAN network DHCP settings to "DNS Server" = "Auto" or manually set it to the LAN IP address of the UDM.
Both methods are tested and working.
That description could be DNS over HTTPS (DoH) or DoT. Try disabling that in your browser. Split DNS only works if the browser is using the local DNS...acting like it's not resolving although it resolves in nslookup.
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.