Building a Secure 3CX Backup Repository
A Practical Approach to Business Continuity
By Gary Asher, The Lauer IT Group
One of the realities of supporting modern business communications systems is that backups are only valuable if they can be trusted.
Recently, I worked through the design of a secure backup repository for hosted 3CX PBXs. At first glance, the project seemed straightforward: install an SFTP server and allow backups to arrive from the Internet.
In reality, building a reliable solution requires much more than opening a firewall port.
It requires planning, documentation, security, testing, and long-term support.
The Business Problem
Many organizations rely on hosted phone systems but don’t always have an independent, secure method for storing backups.
Questions quickly arise:
- Where should backups be stored?
- How should access be secured?
- What happens if credentials are compromised?
- How do we know backups are actually usable?
- Who maintains the system over time?
A backup strategy should reduce business risk—not create additional vulnerabilities.
The TLIG Design Philosophy
Technology should solve business problems—not create new ones.
For this project, that meant designing a solution that was:
- Secure
- Reliable
- Documented
- Easy to support
- Scalable for future growth
The solution combines:
- Windows 11 Pro
- FileZilla Server
- Hosted 3CX PBXs
- pfSense or UniFi UDR/UDM firewalls
- Dedicated DMZ placement
- Encrypted SFTP communications
The objective is simple: protect business-critical communications data while minimizing operational risk.
Security Is More Than a Firewall Rule
Security was considered throughout the project.
Key controls include:
- Dedicated DMZ placement
- Limited firewall exposure
- Strong authentication
- BitLocker encryption
- Windows Defender
- Threat Management
- Geo-IP filtering
- Routine updates
- Comprehensive logging
- Administrative account separation
No single security control should be trusted by itself. Multiple layers provide better protection.
Documentation Matters
One lesson reinforced during this project is that documentation is every bit as important as configuration.
A complete deployment should include:
- Network diagrams
- Public IP information
- Dynamic DNS configuration
- Firewall rules
- Backup schedules
- Customer contacts
- ISP information
- Maintenance schedules
- Recovery procedures
Good documentation reduces downtime and simplifies future upgrades.
HIPAA Considerations
Healthcare organizations should evaluate whether backup files contain Protected Health Information (PHI) or other sensitive operational data.
Even when patient records are not directly stored within the phone system, voicemail, call recordings, contact information, user accounts, and system configuration data may require additional protection.
Access Control
Administrative access should be limited according to job responsibilities and the principle of least privilege.
Audit Controls
Logging should be enabled for:
- FileZilla Server
- Windows Event Viewer
- Firewall platforms
- Threat Management systems
Transmission Security
Encrypted protocols such as SFTP should always be used.
Unencrypted FTP should never be used for healthcare environments.
Backup Integrity
Successful backup creation alone is not enough.
Organizations should periodically verify that backups can actually be restored.
A backup that cannot be restored should be considered a failed backup.
Risk Analysis
This solution should be included in periodic HIPAA risk assessments and disaster recovery planning.
Testing Is Part of Deployment
A successful implementation should verify:
- SFTP connectivity
- Firewall operation
- FileZilla logging
- Backup scheduling
- Manual backup execution
- Restore procedures
Trust—but verify.
TLIG Engineer Tips
Engineer Tip
During initial deployment, perform a manual backup while simultaneously monitoring:
- FileZilla logs
- Firewall logs
- Windows Event Viewer
Verifying all three layers together can save hours of troubleshooting.
Engineer Tip
If an ISP changes the public IP address:
- Verify DDNS.
- Test external port access.
- Verify PBX connectivity.
- Run a manual backup.
Engineer Tip
Always perform a restore test after deployment.
A backup that cannot be restored should not be considered a valid backup.
Lessons Learned
This project reinforced several practical lessons:
- Good security starts with good planning.
- Documentation saves time.
- Testing reduces surprises.
- Standardization simplifies support.
- Compliance should be considered from the beginning.
Most importantly, successful technology projects are rarely about technology alone.
They’re about helping businesses reduce risk and improve operational reliability.
The TLIG Approach
At The Lauer IT Group, projects are designed with long-term support in mind.
Technology should not only work today—it should remain understandable, maintainable, and secure for years to come.
That philosophy influenced every aspect of this project, from network segmentation and firewall design to documentation standards and ongoing maintenance planning.
Companion Technical Guide
This article accompanies the TLIG Technical Guide:
Secure SFTP Backup Repository for Hosted 3CX PBXs
The complete guide includes:
- Project planning
- Windows preparation
- FileZilla Server deployment
- Hosted 3CX configuration
- pfSense implementation
- UniFi Zone Based Firewall configuration
- Security hardening
- HIPAA considerations
- Validation procedures
- Troubleshooting
- TLIG Engineer Tips
- Maintenance recommendations
The goal isn’t simply to build an SFTP server.
The goal is to build a reliable, secure, documented, and supportable backup solution that protects business operations.
Technology should solve business problems—not create new
