• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

Unsupported Cisco SPA504 provision issue

Status
Not open for further replies.

gogos125

New User
Joined
Sep 20, 2021
Messages
8
Reaction score
1
Hello to all,

I just set up 3CX in AWS Debian 10 and I am trying to provision a cisco spa504 with firmware 7.6.1. I can see the XML file on the browser but the cisco device after the message

"SPA will resync the profile when it is not in use and reboot.
You can click here to return to the configuration page."

doesn't do anything, I have reset the phone. Any suggestions? I am new to 3CX so I follow the guides. Mac address is correct.
 
Hello,

As per our guide, you will need to run DHCP Option 66 on your local network in order to make these provision themselves.

You also need to download and install the Cisco SPA support files linked in the guide.

They are only supported in LAN deployment (ie. the PBX and the phones will be on the same LAN).

https://www.3cx.com/sip-phones/cisco-spa/
 
Hi follow this video I made, its not the same phone but will still work
 
I followed that guide that 3cx made I could not get it to work to save my life, I even tried it on a local deployment.
However with some tinkering I got it to work with my AWS deployment.
 
Thank you this works great with my also AWS deployment. If I set up SBC in a Debian VPS in the cloud will this work?
 
No the sbc is meant to be a physical device on your lan. Its essentially a gateway for your ip phones
 
Ok, i just spin up the SBC Debian version on a cloud VPS and i don't know how but it works. I can call and receive calls from other extensions in my cisco spa504g. Just changed the proxy point at VPS ip
 
Ok, i just spin up the SBC Debian version on a cloud VPS and i don't know how but it works. I can call and receive calls from other extensions in my cisco spa504g. Just changed the proxy point at VPS ip

Then why not skip the extra step of the SBC, and connect to the PBX directly?
There is no point in remotely connecting to a public SBC when you can remote connect directly to a PBX. It's just STUN mode with an additional step in the middle. There are also security considerations because the SBC is exposed while it was not designed to be exposed.

While there are many things that you can experiment and make them work, it does not mean that it was designed to work that way or that it will continue to work reliably.

If it is just for testing or experimentation there is no problem, but these devices have not been tested to work outside of purely LAN conditions, so if they are critical to your work, I would not consider this setup reliable or secure enough for production.
 
I cant register directly to pbx it says Registration State: Failed - 403 . As I mentioned I am new at 3cx and I just want to test/experiment.
 
By default the system does not allow remote registrations (for security reasons).

STUN extensions need to have this option unticked, in order to allow remote registration:
Extension >> Options >> Restrictions >> Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)
 
Ok, now it worked! So but this way has security issues you said. Is there any limit for how many devices(on 1 site) can work with stun extensions?
 
Theoretically yes (you don't have infinite ports) but I don't think you will ever reach such a limit..

You could (via firewall rules) limit port 5060 of the PBX to only be able to talk to your remote phones site, and your trunk provider, thus reducing the possibility that anyone can register on your PBX.

Or you could setup a VPN between the PBX in the cloud, and the phones site, and you can then not have to deal with STUN at all (since the phones will appear as LAN phones to the PBX).

The most ideal solution is to set up a SBC inside of the same office as your phones. They need to be on the same network, behind the same firewall.

This does not require STUN, or port management, or complex VPN setups, or allowing extensions to register remotely. The SBC literally takes care of all these issues.
 
Ok, I understand that with SBC is much easier. Can I use SBC on-premises with many ip phones and use the STUN for the few IP phones outside of the network? e.g my home
 
Sure you can. You can have upto 100 extensions per SBC so you only need one if you have less than that at your office. And you can set the few remote phones as STUN. You can have a mix of multiple SBCs and multiple STUN phones, and multiple Local phones if needed.

Scroll down to SBC to see the requirements for the right size of VM, PC or even Raspberry Pi where the SBC can run from: https://www.3cx.com/docs/recommended-hardware-specifications-for-3cx/
 
Thank you very much for your information, I appreciate that!! That's why I want to use 3CX, for the support!! Although the devices are legacy,
 
If you can get your hands on some supported devices though, you can gain more features that are not found on the current phones you have:

  • PnP Support
  • STUN Support
  • SBC Support
  • Full CTI Support
  • BLF Functionality
  • Company Phone Book
  • DST Support
  • Firmware upgrades, deployable via the management console
  • Template updates
  • Better TLS security and ciphers

..so keep that in mind going forward ;)
 
Yes, I totally agree but it's not easy to replace 40-50 devices. I managed to change some users to use the mobile app though!!
 
  • Like
Reactions: JohnS_3CX
Yeah that's understandable and the app solves quite a few issues since everybody already has a phone or PC.

At least you can be aware going forward, and if you have any other questions on other subjects you can always feel free to ask!
 
  • Like
Reactions: gogos125
Status
Not open for further replies.

Forum statistics

Threads
112,147
Messages
590,959
Members
165,167
Latest member
Finatra.us