TIPS New install (in the cloud)

hashkent

New Member
Joined
May 5, 2011
Messages
6
Reaction score
0
So I'm planning on a new PIAF install in a VMware based VPS with a provider in a DC.
I am thinking 512MB ram, 20GB space, 1 CPU core - Is this enough? There next plan up is 1GB ram, 40GB space, 2 cores, but a little pricer... This is an AU location so bandwidth and costs are high, provider also offers Xen Server however I think that wouldn't be as good as VMware?

I'm planning for 8-10 inbound calls at G711, queued up remotely until the Polycom / Cisco users answer (2-3 on a call rest queued remotely).

I understand VMware is very good for PIAF and latest versions of Asterisk, with no chopping on hold music so this is important. I am doing it this way so calls can be queued remotely and we can answer everybody, rather than having choppy / broken calls queueing locally :)

I will then have aprox 5 extensions hanging off that
3 x Polycom 560 Static IP behind NAT (Will try https provisioning, will they accept self signed SSL?)
2 x Cisco 7960 - Static IP behind NAT (looking at static provisioning using local t*f*t*p server, should still boot OK with saved configs once tested and working)
Gigaset C470IP - Dynamic IP behind NAT, manual provision in web interface
Mobile device SIP client (e.g 3CX) - Dynamic IP behind possibly double NAT over 3G (assume good data speeds).

Is their an up to date guide on securing PIAF in a public IP / VPS environment? I've read things such as only create dialling plans to destinations you'll call etc and set times you can call them (e.g business hours), but aside from that sort of thing what other ways can I secure my install?
I can't quite use IP tables to block the world except SIP trunk and end points, because of dynamic IPs. I'd like to avoid VPN unless I really need to.

Trunks are prepaid so if I get hacked i'll only lose $20-30 per trunk provider (about 4 trunks so $100 max).

Very keen to hear peoples thoughts. Once deployed i'd look at providing a step by step guide for others :)
 
Do yourself (and your checkbook) a favor. Do a lot of reading before you attempt to deploy a cloud-based Asterisk solution of any flavor. RentPBX is a financial and technical backer of our project with YEARS of development experience in their cloud platform. At $15 a month, their service is a terrific bargain; however, it's still a dangerous platform if you're new to all of this. Read the Travelin' Man 2 and Travelin' Man 3 tutorials on Nerd Vittles for some background on WhiteLists. They will do what you need IF you are running PBX in a Flash or Incredible PBX. You really do not want a cloud-based solution without a firewall AND a whitelist!

I'd strongly recommend you start with a VirtualBox-based virtual machine on your desktop to get your feet wet. It will operate just like a cloud-based solution without the security worries. Once you're comfortable with the platform and understand the security risks, then you can move on to a cloud-based solution. Good luck!
 
I would second Ward's comments. I have installed a number of stock Centos VPS systems with FreePBX and I've never had a trouble free install. Look at RentPBX first. PIAF does work fine on VMware 4 or 5 in my experience.
 
Indeed we still develop on vmware (workstation only not ESX!) proxmox/virtualbox/ Xen with few problems however RentPBX is the way to go and you don't have to be a linux/cloud god to make it work.

Tom
 

Members online

No members online now.

Forum statistics

Threads
26,686
Messages
174,406
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top