• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

Solved 3CX Phones PNP but won't Provision

Status
Not open for further replies.

clearedgeseth

Basic Certified
Joined
Oct 6, 2020
Messages
12
Reaction score
5
I did a new install today and cannot get the phones to provision. The setup is as follows:

1. Windows Server 2016 Hypervisor with the 3CX Debian install running on a hyper-v VM. (I followed the guide found here - https://www.3cx.com/docs/installing-microsoft-hyper-v/ to configure the VM and followed this guide to do the install - 3cx.com/docs/manual/installing-debian-linux-pbx/)
2. Flat network (no VLANs) with the phones on the same LAN as the 3CX install.
3. Linksys router and Netgear GS752TPv2 switch (one cable from router switch to Netgear and all other devices connected to Netgear switch)

- I connected three different Yealink phones (T46S, T42S, T40G)
- All phones show as 'NEW' in the phones tab
- I can ping from the phones to the server without issue

I have followed the standard process of checking the phone and assigning it to an existing extension and the phone simply won't provision.

I also tried to manually add the phones to an extension with the MAC and select local LAN and they will not provision.

I tried to put the provisioning URL (the URL is correct) in the server field on the T46S and that won't work.

I have updated the firmware on the phone to the supported version of 3CX and factory reset several times.

Each time the phones show up as 'NEW' but I cannot get them to provision following any method (https://www.3cx.com/sip-phones/yealink-t4-series/).

Any help is greatly appreciated.
 
Hi,

Did you check the 3CX blacklisted IP whether your local phone IPs are getting blacklisted?

And try to turn off the "Trusted Certificate" in your Phone setting and then proceed with your configuration process.

thanks,
RA.
 
  • Like
Reactions: ahren
Hi @clearedgeseth

Some questions:

1. What version is your PBX
2. Have you made any modifications to 3CX system files/templates or followed the official way?
3. What firmware version is the Yealink running?
4. Have you also installed the NTP service as per the Hyper-V guide?


Some suggestions:

1. Connect a PC to the same network as the phones
2. Try to download the config file manually to see if it is reachable by entering this url:
http://{3CX_LAN_IP}:5000/provisioning/{random_id}/{phone_mac_address}.cfg
example: http://192.168.1.100:5000/provisioning/szfk0qjapl/000145789654.cfg

Is it downloadable?
 
@Cal4care | RA - The IPs are not blacklisted as the phones are on the local LAN.

@JohnS_3CX

1. Version - 16.0.9
2. I haven't made any modifications to the system files/templates at all. I did an official install yesterday without making any modifications.
3. Yealink T46S v66.84.0.35 (version according to 3CX website)
4. Yes

When I try to browse to the URL mentioned (http://{3CX_LAN_IP}:5000/provisioning/{random_id}/{phone_mac_address}.cfg) I get a 403 error. '403 Forbidden'.

Thanks for the help!
 
Ah I see, it might just be a small misunderstanding about the versioning.

If you check our guide, 66.84.0.35 is not the latest, it's just the minimum version needed to be installed before you can proceed to install the latest which can be found here

As for the 403 forbidden, that is not a very good sign. Something is preventing both the PC and the phone from downloading the config file and this is why the provisioning is failing.
 
Last edited:
So firstly click here in your management console, and make 100% sure there are no blacklisted IPs (this would definitely cause a 403)
1628084970437.png


Then, also tell us what IP range is the PBX in and what range are the phones in?

The acceptable ranges are as per RFC1918 10.0.0.0/8,169.254.0.0/16,172.16.0.0/12,192.168.0.0/16 so if your are outside of those you should not be able to get the provisioning file over plain http.
 
Last edited:
@JohnS_3CX

The PBX and phones are in 172.50.50.0/24. I added it as whitelisted IPs, but I'm guessing that is my problem.

Is there anything I can do to get that subnet to work or am I better off reinstalling and starting from scratch with one of the above subnets?
 
The 172.16.0.0/12 private network allows the following range of valid IP addresses: 172.16.0.1 to 172.31.255.254 so in this case you are in an unsupported IP range. The range you are using is in the public IP address space, so the system will not accept the provisioning request coming from the phone (it is indeed forbidden). So in simpler terms, this is in the WAN range, not the LAN range.

I suggest you redeploy your system within the RFC1918 address space in order to have your system run as designed.
 
Will do. Thanks for your help! I'll blame the network guy :)
 
  • Haha
Reactions: JohnS_3CX
You're welcome! Don't be too hard on him, he probably did know :p
 
I rebuilt the system and put it in a LAN subnet and all is well. Thanks again for the help! Please mark as solved.
 
Status
Not open for further replies.

Forum statistics

Threads
112,147
Messages
590,959
Members
165,167
Latest member
Finatra.us