Docs navigation

Bridges

A bridge links two phone systems so extensions on each can dial the other with a prefix: with prefix 8, dialing 8100 reaches extension 100 on the remote system. One side is the master (it mints the bridge credential), the other the slave (it registers to the master). Exovo bridges to another Exovo, or to a 3CX system — the design driver is gradual migration, where a 3CX stays master while sites move to Exovo one at a time.

Create bridges under Admin → Trunks → Add Bridge. The dial prefix's outbound rule is created automatically on the side you create the bridge on.

Exovo ↔ Exovo (tunneled — the default)

An Exovo↔Exovo bridge runs through the master's mTLS tunnel by default: certificate- authenticated TLS for signaling and an encrypted UDP media plane, all through the master's single tunnel port (5090). The slave needs no firewall changes at all — it only dials out.

  1. On the master: Add Bridge → This system is the master. The one-time credentials card shows the tunnel server address, an enrollment key, the bridge number, and the password.
  2. On the slave: Add Bridge → Connect to an Exovo masterTunneled, and enter those four values. The slave enrolls with the master (the key is one-time and expires in 7 days), receives its own client certificate, and connects.

The certificate is scoped to the bridge number alone — a bridge peer can never register or impersonate anything else on the master. Bridges show a lock on the Trunks page when tunneled.

Direct SIP remains available for Exovo↔Exovo (choose it on the slave) when both systems already have SIP/RTP reachability — the same firewall requirements as a carrier trunk.

Exovo ↔ 3CX

Exovo connects as the slave of a 3CX master bridge (direct SIP):

  1. On the 3CX: create a Master Bridge, direct connection (SIP, port 5060). Note the bridge's virtual extension number and password.
  2. On Exovo: Add Bridge → Bridge to a 3CX system, enter the 3CX address and those credentials.
  3. On the 3CX: create the outbound rule for the bridge prefix yourself — 3CX V20 does not create it automatically.

Mind the password: 3CX blacklists the peer's IP after 5 failed authentications — copy-paste, never retype.

Numbering and caller ID

  • Exovo tolerates extension numbers that exist on both systems (something 3CX↔3CX bridges cannot do) — but a caller on the other system dialing a number that also exists locally will always ring the local one. For migrations: when an extension moves, delete or renumber it on the old system.
  • Caller names travel across a bridge in both directions. Toward a 3CX, the caller's number displays as the bridge ID — that is standard 3CX bridge behavior.

Limits

  • Bridge calls terminate on the remote system's local destinations; a caller cannot ride the other system's outside lines (no toll-through).
  • Presence/BLF does not federate across a bridge.
  • Changing a bridge's dial prefix later does not update its outbound rule — edit both.