• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

Firmware Upgrade Fails HTTP/HTTPS MisConfig

Status
Not open for further replies.

JordanRN

Forum User
Joined
Aug 21, 2017
Messages
10
Reaction score
1
I am trying to upgrade the firmware on my phones through the console, however it does not seem to be working for most. This is the access log from the server itself.

Recently upgraded from 15.5 SP6 to 16.0.9.

I think my issue stems from a http/https misconfiguration. If I set the phone provisioning/update from https to http it'll update the phone just fine. But doing this for over 200 phones is not feasible.

Server Version: 16.0.9 Professional Perpetual
Phones: Grandstream GXP2170

XXX.XXX.6.179 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x03\xE6+\xDB\x09\xB0j\x0BO\x1A\xD52\x12&C\x05C\x7FB\xDD\x8F7Y\xB7\xF7\x84\xA61\x17S\x11\x85\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.179 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x07\x90" 400 150 "-" "-"
XXX.XXX.6.179 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xBAM2E\xC1^\x04~\x0F8\x1B\x5C^\x01Nw\x9FX\xCB\xB0\x97\x1C\xA0\xD8\xDA~2\xDD\x0Ez;\xC3\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03}\xA8\xB3\xD5\xFE\x0E~\x09^\xFCQ\x12uZ%\x0B\x0E\xB7\xE0\xB1\xEA\x22\xE4\xB5\x04\xF7#\xF9gD\xF4U\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xD6\xB9S/\xD7\x1A\x8B\x89\xEDH\x82g\xF1\xDC;\x90M\xA0\x5Cb3\x01\xC2\xE5\x17" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x1A\xDD\xF0\xD6\x0BC\xAA\xD0\x0B[\xD5`\xCBfA\xA63\x91\x1E\xE5\x8AP@pd=?\x8A\x8F~\xA1j\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xC1P\xDA\x83\xBB#`\xF8\x0E\x00t\x8E\xE8L\x84,\xF30\x80\x99r4\xB6\x15\xA7y\xBDe\x95q\xFF\xDC\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xE4})@Im(\xCC\x81\xCC\xB2\xDA\xF4t\xEC\x19_7\xA1\x0B*O\x10\xB7\x17\xB0\xF1-y]\xE4+\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x19\xEE\xFB%\xB4\xF0&\xCD-\xD2\xC8C\x98\xD9,\xC9:\xF8\xFF\xB8\xF1\x10\x16\xCE\xA4lgG9\x8D\x81" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03?\xFCx\xF4\x84\xD6\xAE\x22\xB1V\x053@\xF5k-\xC12>\x98T.b\xD3r>\x0F\x13\x88\x9A\xAD\xE6\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03nr\xCE/\xE0\x9C8\xFEs\xBEY\xDC\xF5\x1C\xCF(\x9Dq\x90\xD8\x85\xCEt\xFA\xB5\xCC(]Z\xAB\x88N\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03P\x85X\x9A\xFC\xE71\x8A\x0E\xB8\xB4\xD1\x9E\xC8w\xAB\x97\x96X\xA7\xB1\x99n\x98\xD7V(\xA0G\xD7;|\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03V\xB5\xDE\xE3\x98\xCB\xD1QQ\xF0\xDB\x96m\xC5P\xD2;3\x857r\xFDA\xB8\x05\x15\x95}4}\x006\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x90\xC3\x1E\x1D\x9A\xE9y\xC0r\x97\x83\xB2)\xED\xA5\xD7\xD59\xBA\x03\x1C_\xE5\xF4\x84\xF2s\xC9h\xE8\xCA\xB9\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03Tn\xC2\xEF-Ei\x08\xE2\x87<\xA3D\x8Dhy\xBF\x02\xE8\xF2\x95U\xAE\xFFh\xA3\xD8m\x17u6x\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x85\x12\x02\x85\xA68{\xE6$\xFD\xF3\xD4\x8FHu+6\x85\x9E(\xBBv\xEE\x89\xB1i\xD4\xF2DB\xB6\x9B\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:18 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03Jt\xF4p\xBDw\xBB\x03\x0E\x94\xEE\xA2\x1D\xAC\xDC\xFF\xC7\xA6d*\x0B/\xCB\xA4_\xB2\x8E\x9AP\xFDe`\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03n\xC4\x1A~=\x8Ag\xF5\xDD\x9E\x99!1\x8F\xD1\xB8@Ds\xD0\xBE\xFCy\xA13\xA0\xFB\x9BO\x10\xDF\xA3\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03I\xA2E\xD2M'c5pO!\xCB\x92N\x12\x07\x884:8\x8F7.\xBD\x9E\x02\x17i\xC7RM\xDE\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03b\x80&\x18)\xFCK\xA2<?[\x00\xC3\x02\x007\x9E\xB8\xC9\xA3\xBC\xBFD)\xA4\x9B\xF1~\xFC<\x8AP\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xE2i;\xC4\x1A\xBB\xEF\xEA\xF2\x1B+W\x9D\x8B\xD3\xC6/\xDE:\xFF\x1B\xC9\xA4U:\x0F-\xFD?\xDE*\xA7\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x86\x00(,?\xA6T\xE8`\xFDz\xCA\xC8Z{\xE7\xBC.\xAC\x1DH\xC3\x0C\xAA\xA9\xED\x9C.e\x02\x22\xF2\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03O&4\x9A\x1B\x9A\xA4\x04=d\x12s\x8A\xBE~\xF8\xE4%\x1F\x0B\xFC%\xA9\xE8'\xD7<\xCF\xC0\x80\x00t\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x14\xC7\x02,\xA0\x88o5\x9A\x09S\x89\xBA\x09\xCF\xF1\xDE\xA2\xD0_\x14\xE5\x95\xBCx\x85\xCB^\x01\xD5\xE3?\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x90\xEA??\xF1\x98\xBB\x22\x7F\x92'\x97\xA2\x0B\x111Z\xA2\xCF\xE0[U\xA6\xF1SWn\xF3\x9C\xCDF\xBD\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"
XXX.XXX.6.225 - - [30/Jul/2021:07:57:19 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xD7\xDE\xF4\xD6*6>\xF7\x0BD" 400 150 "-" "-"
 
Chris,

When I log into the Phones UI->Maintenance-> Upgrade and Provisioning->Config / Firmware I change the Upgrade Via from HTTP to HTTP
 
With that change only you would probably end up with the port not matching unless you're using the default ports 443 for HTTPS and 80 for HTTP.

In any case, how are the phones provisioned, are they provisioned as Local,SBC or STUN deviceS? Also, where are they actually, are they local to the PBX (same LAN) or on a remote location with or without an SBC?
 
Chris,

Config Server path looks like: XXX.XXX.1.111:5000/provisioning/random_chars
Firmware Server path looks like: XXX.XXX.1.111:5000/provisioning/random_chars/firmware/grandstream

Phones are all local to the server, different VLAN of course. Provisioned Local

Using the FQDN to any of those paths, web browser throws up an ERR_SSL_PROTOCOL_ERROR

Below is the nginx.conf file.
#user nobody;
worker_processes auto;

#error_log logs/error.log;
#error_log logs/error.log notice;
#error_log logs/error.log info;

#pid logs/nginx.pid;


events {
worker_connections 10240;
}


http {
map $http_upgrade $connection_upgrade {
default upgrade;
'' $http_connection;
}

include mime.types;
default_type application/octet-stream;
#limit_req_zone $binary_remote_addr zone=perip:50m rate=1000r/s;

#log_format main '$remote_addr - $remote_user [$time_local] "$request" '
# '$status $body_bytes_sent "$http_referer" '
# '"$http_user_agent" "$http_x_forwarded_for"';

#access_log logs/access.log main;

sendfile on;
#tcp_nopush on;

#keepalive_timeout 0;
keepalive_timeout 65;

#gzip on;


server {
add_header X-Frame-Options "SAMEORIGIN";
listen 5000;
listen [::]:5000;
server_name voip.FQDN.com;
server_tokens off;

#access_log off;
error_log nul crit;

allow XXX.XXX.0.0/22;
allow XXX.XXX.8.0/24;
allow XXX.XXX.6.0/23;
allow XXX.XXX.0.0/12;
allow 10.0.0.0/8;
allow 127.0.0.1;
allow ::0/0;
deny all;

client_max_body_size 300m;

location /user_images {
include "shared-headers.conf";
expires 1y;
add_header Pragma public;
add_header Cache-Control "public";
root "C:/ProgramData/3CX/Data/Http/wwwroot";
}

location ~ /webclient/.*\.(png|js|css|woff|woff2|json|mp3)$ {
include "shared-headers.conf";
expires 1y;
add_header Pragma public;
add_header Cache-Control "public";
root "C:/ProgramData/3CX/Data/Http/wwwroot";
}

location ~ index\.html {
include "shared-headers.conf";
add_header Cache-Control "no-cache, no-store, must-revalidate";
add_header Pragma no-cache;
expires 0;
root "C:/ProgramData/3CX/Data/Http/wwwroot";
}

location / {
include "shared-headers.conf";
index index.html;
root C:/ProgramData/3CX/Data/Http/wwwroot;
try_files $uri $uri/ @proxy;
}

location /MyPhone {
include "shared-headers.conf";
alias C:/ProgramData/3CX/Instance1/Data/Http/Interface/MyPhone;
try_files $uri $uri/ @proxy;
}

location @proxy {
include "shared-headers.conf";
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_pass http://127.0.0.1:5004;
proxy_buffering off;
}

location /management/Reports {
include "shared-headers.conf";
alias "C:/ProgramData/3CX/Instance1/Data/Http/Reports";
}

include "snippets/*.conf";
}


server {
add_header X-Frame-Options "SAMEORIGIN";
listen 5001 ssl http2;
listen [::]:5001 ssl http2;
server_name voip.FQDN.com;
server_tokens off;

access_log off;
error_log nul crit;

ssl_dhparam Instance1/dhparam.pem;
ssl_session_cache shared:SSL:60m;
ssl_session_timeout 1d;
ssl_stapling on;
ssl_stapling_verify on;
add_header Strict-Transport-Security max-age=15768000;
ssl_protocols TLSv1.2;
ssl_certificate Instance1/voip.FQDN.com-crt.pem;
ssl_certificate_key Instance1/voip.FQDN.com-key.pem;
ssl_ciphers 'EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRSA HIGH !RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS';
#ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:!DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA:!ECDHE-RSA-DES-CBC3-SHA:!ECDHE-ECDSA-DES-CBC3-SHA';

ssl_prefer_server_ciphers on;

client_max_body_size 300m;

location /user_images {
include "shared-headers.conf";
expires 1y;
add_header Pragma public;
add_header Cache-Control "public";
root "C:/ProgramData/3CX/Data/Http/wwwroot";
}

location ~ /webclient/.*\.(png|js|css|woff|woff2|json|mp3)$ {
include "shared-headers.conf";
expires 1y;
add_header Pragma public;
add_header Cache-Control "public";
root "C:/ProgramData/3CX/Data/Http/wwwroot";
}

location ~ index\.html {
include "shared-headers.conf";
add_header Cache-Control "no-cache, no-store, must-revalidate";
add_header Pragma no-cache;
expires 0;
root "C:/ProgramData/3CX/Data/Http/wwwroot";
}

location / {
include "shared-headers.conf";
index index.html;
root "C:/ProgramData/3CX/Data/Http/wwwroot";
try_files $uri $uri/ @proxy;
}

location /MyPhone {
include "shared-headers.conf";
alias "C:/ProgramData/3CX/Instance1/Data/Http/Interface/MyPhone";
try_files $uri $uri/ @proxy;
}

location @proxy {
include "shared-headers.conf";
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_pass http://127.0.0.1:5004;
proxy_buffering off;
}

location /management/Reports {
include "shared-headers.conf";
alias "C:/ProgramData/3CX/Instance1/Data/Http/Reports";
}

include "snippets/*.conf";
}

}
 
If they are local then you should keep it on HTTP. What happens exactly when you try to upgrade a phone via the console? Do you get an error message?

IP Phones will upgrade the firmware by contacting the 3CX PBX on the HTTP/HTTPS port. Same way as they would do to reprovision. That said, could you check if reprovisioning works for a phone that cannot upgrade? Just add a new BLF to it via the Management Console, save it, go to the "Phones Section", find the extension/device selecting and hit reprovision. Does the new BLF key get provisioned?
 
Chris,

When I try to upgrade the phones from the 3CX Admin Console before making any changes, nothing happens. The log in first post is what I get with the HTTP Error 400.

When I try to reprovision the phone from the 3CX Console, it does not update. No error gets thrown except in the access log.

Access Log
XXX.XXX.8.24 - - [30/Jul/2021:09:11:16 -0400] "\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x031\xEF\x1F\xBE8\xC5\xF9\xE3\x97\xB4\xE2\xFC\xB9\xBE\x90\x7F\x01\x9Cil\xA7\xC1c\x1DO\xC3\xF7\x15\xA4]#\x87\x00\x00\x84\xC00\xC0,\xC0(\xC0$\xC0\x14\xC0" 400 150 "-" "-"


Seems all of my phones are provisioned for https instead of http... Any easy way to change this globally without logging into each phone?
 
Are you perhaps using a custom templates for these devices?

Based on the provisioning link you provided, the port used within it is the HTTP port but you say that the protocol used is actually HTTPS on the phone. There is no configuration that can be done within 3CX that would result in this situation so I can only assumed something was modified or custom templates are in use.

I think your best option would actually be to factory reset all these affected devices and re-provision using the default template. If you want to automate this process a bit, you could potentially use something like DHCP Option 66.
 
Chris,

I do believe there was the custom grandstream template before grandstream phones were supported.

On the factory reset, would I have to do anything within the assigned extension or would it auto provision since the MAC is already assigned?
 
On the factory reset, would I have to do anything within the assigned extension or would it auto provision since the MAC is already assigned?
Provided you're talking about a configuration with DHCP Option 66 then yes.

If not, I'm afraid no, after they have been reset, you will be able to to see the phones come up in the "Phones" section in the Management Console where you would have to simply select them, click on assign extension and then apply the configuration.
 
Thanks, we currently have DHCP Option 66 in use so this should be a breeze.

Thanks!
 
  • Like
Reactions: ChrisC_3CX
Excellent!

I do of course recommend testing it out with at least one device first.;)
 
  • Like
Reactions: JordanRN
Excellent!

I do of course recommend testing it out with at least one device first.;)
Chris,

Do you know if the current grandstream firmware supports LLDP Med for VLAN configuration?

Thanks!
 
You can toggle LLDP on or off for the GXP2170 via 3CX however I'm afraid I am unsure of LLDP-MED. I'd recommend consulting the vendor's documentation for this.
 
Status
Not open for further replies.

Forum statistics

Threads
112,149
Messages
590,964
Members
165,170
Latest member
SupportRock