r/yeastar

I see a lot of activity in this sub-reddit for 3CX refugees. I have been looking at yeastar, but it seems like needing a VM for every customer and a license for every customer is a lot of extra management vs a multi-tenant solution.

Has anyone tried Thirdlane multi or single tenant and can provide feedback?

reddit.com
u/GCDavidC — 9 days ago

I’ve been looking into a P-Series "Software Edition" install lately and I’m struggling to find any reason to use this over a physical appliance or a proper UCaaS setup. It seems to just combine the worst parts of both.

The install is the main red flag. You have to give the script root access to your box, but then it essentially uses that access to lock you out. It forces the installation of a bunch of OS-level libraries pulled directly from Yeastar's own servers instead of standard distribution points. Once it’s done, it sets up a "support" account that’s stuck what seems like a fairly restricted shell. I don't mind them moving the SSH port or disabling password auth, but they've done it in a way that makes it incredibly difficult for the actual owner to manage the underlying OS.

If you need to run EDR agents, vulnerability scanners, or standard endpoint monitoring, you're basically forced to use your hosting provider recovery console just to regain the access needed to install them. You shouldn't have to perform a manual rescue operation on your own VM just to get a security agent running. It completely breaks any standard automated deployment or SOE workflow.

Then there’s the firewall. There is a daemon running in the background that manages iptables, and it comes pre-loaded with firewall rules. On paper, they’re seem to be for things like their global anti-hacking database, updates and remote infrastructure, but it's a fairly crude whitelisting of a huge range of Alibaba Cloud IPs on every single port. You can delete them in the web UI, but since the system is architected to rely on those foreign-hosted services for its features, you’re stuck choosing between breaking their functionality or leaving a permanent hole in your perimeter.

The biggest issue for me is maintenance. Because the PBX software is tied to those unverified library versions, you can’t really run a standard apt upgrade or patch the OS without risking updates messing with the those non-standard libraries they pull during the install process. You’re basically stuck with a frozen box that you can’t independently verify or update easily.

It feels like a product for an MSP that wants the cheapest possible "set and forget" option, but if you’re in a place that actually has security requirements beyond blocking public internet access and hoping for the best, it's an issue. You don’t hold the keys to the server by default, and you can’t maintain a standard security baseline without getting into brawls with how the install process has configured the operating system.

If I wanted a black box I couldn't touch, I’d have just bought the hardware appliance. This "Software Edition" just feels like an appliance wearing a VM's skin. Has anyone actually managed to get one of these into a state where it passes scrutiny from an organisation that cares, or is it just not built for that level of scrutiny?

reddit.com
u/Educational-Art-8515 — 12 days ago

I'm new to Yeastar, just purchased a new trial of Yeastar PSE 2 weeks ago, selected Yeastar P- series droplet on Digital Ocean and successfully installed a customer with 40+ extensions and Yealink phones.

My first setup was so smooth but i just can't understand what am i doing wrong or differently when setting up another trial PSE and another digital ocean droplet.

Differences are as follows

  1. I'm not seeing the status center in any new PSE i create even though I'm logging in as super admin, i only see the dashboard which means i can't see the "Active Calls" section. I do see the Status Center in my first instance though that i created 2 weeks ago so what changed in 2 weeks from Yeastar side.

  2. When the PBX reboots 1st time after configuration , i login and get asked to set FQDN, the subdomain appeared in my first installation was ras.yeastar.com but now it shows as ras.uccpbx.com. In my first install, it was mydomain.ras.yeastar.com and now it shows as mydomain.ras.uccpbx.com even though the method of installation is exactly the same

  3. When i want to add a new phone, in the provisioning method drop-down, the RPS FQDN method is missing. I'm only seeing IP method and PnP method

reddit.com
u/CupRough4307 — 12 days ago