Solved Grandstream GXP1620 - Won't provision - Gateway Timeout

Status
Not open for further replies.

MrGeezer

Customer
Joined
May 29, 2019
Messages
25
Reaction score
4
Hello,

I have purchased a Grandstream GXP1620 which I want to use as a remote extension at home. I already have one in the office on the LAN and it works fine.

I have used the Phones menu to add a phone and type in the phone's MAC address. I then followed the instructions to get the provisioning link from 3cx console and enter it as the link to use in the grandstream phone's web-setup menu.

When I reboot the phone, it does not provision and get assigned the extension.

When I look at the server console I can see the following warning

RPS request for GrandStream GXP-1620 IP Phone of My Name (101) NOT delivered. You will need to configure the phone manually by copying and pasting the provisioning link https://my-domain.3cx.co.uk:5001/provisioning/unxniyzw1frjsqc/ in the phone web interface. Error Message: <html> <head><title>504 Gateway Time-out</title></head> <body bgcolor="white"> <center><h1>504 Gateway Time-out</h1></center> <hr><center>nginx</center> </body> </html>

When I go back to the list of phones, the one I created for the new grandstream isn't there. However, if I try to create it again I get an error stating that MAC address has already been used for an existing phone. Furthermore, the message about copying the provisioning link doesn't seem to make any sense - since I have already done that as-per the 3cx documentation instructions.

Is the gateway time-out reference to a firewall problem? I am able to use my windows 3cx client to connect to this extension when I am at home so don't see how that could be??

Thanks,
 
So I'm kinda confused about your setup. First of all, phones only show up in the phones tab when they are registered, which is why you don't see it. It should be listed under the 'Phone Provisioning' tab of the extension. The message about the provisioning link makes sense because 3CX is not clairvoyant. The standard method of provisioning a remote (STUN) phone is via RPS which is what 3CX attempted to do. Since that failed, it's recommending you use the method of putting the URL via the phone web interface which is just the default message. It has no idea you already did that.

Since you mentioned reading the instructions can you confirm the phone is already on the recommended firmware level? That is Step 1 and not having a new enough firmware would stop the phone from provisioning. You also don't mention where your 3CX server sits. The gateway timeout could be a firewall issue but most likely it was simply an issue with the 3CX server responsible for pushing the RPS request to Grandstream or a problem with the Grandstream RPS itself.
 
Hi there, thank you for your reply as I'm sure you can tell I'm a 3CX newbie!

Firstly yes you are correct the phone is under extentions->phone provisioning, sorry about that.

The firmware on the grandstream is 1.0.4.132 and I've done a factory reset.

I am now not even getting a message of any kind in my 3cx dashboard, not a failure message or anything. The grandstream is updating the date and time after it reboots and connects to network, but doesn't appear to be connecting to 3cx prvisioning link.

I have also checked the two options 'disallow use of extention outside lan' and 'block remote tunnel connections...' and both are unchecked.

The 3cx server is behind a firewall in my office. I setup the 3cx windows client app on my laptop using the the copy and paste setup and it works both inside the office LAN, and from my house, implying there is no issue with firewall at either location I think?
 
Hello @MrGeezer

There are 2 ways to provision a STUN phone with 3CX. The first is by adding the phone under the extension and clicking OK. The PBX will try to contact the Grandstream RPS server. If that is successful then once you restart the phone it should try to contact the RPS server and get the config from there. This fails for you either because your server cannot contact the Grandstream RPS server or because the Grandstream RSP server is not reachable (i tried adding a phone and the RPS server works). Also chck if the MAC address of the phone is correct under the extension settings.

The other way is to manually copy the provisioning link under the extension settings and add it to the phones web interface. This procedure is outlined here: https://www.3cx.com/sip-phones/manually-provision-supported-grandstream-gxp/

The phone will request the configuration through the https port of the PBX so make sure that is reachable.

The 3CX clients might work as they work differently. 3CX clients are using the tunnel to contact the 3CX PBX which runs on port 5090.

So from the network the phones are located try to access the management console of the PBX. That should tell if the https port is reachable from your network.
Once you confirm that the https port is reachable, try to factory reset the device and try the manual procedure outlined in the guide above.
The device should be able to provision, meaning you will see the 3CX related settings onto the phone.

Also check that all your 3CX services are running, especially the Nginx service.
 
Hi there,

I am currently in the remote location (home). I don't have VPN it's all remote desktop so I am definitely not inside the LAN of my PBX. I have done the following:

  • browsed to https://my-domain.3cx.co.uk:5001 and sucessully logged into my management console.
  • Logged in to the actual windows box hosting 3cx and ensured the nginx service (and all others except the 'hotel' one) are running
  • Done factory reset on phone
  • Logged into phone web-admin and verified version is 1.0.4.132
  • In phone web-admin, made sure 'always check for new firmware' is ticked
  • Under config, selected 'HTTPS'
  • Set server config path to the provisioning link in my phone provisioning tab
  • Rebooted the phone

Still nothing. The phone doesn't obtain any SIP settings or ask for my user/pass. The management console event log doesn't show any message about allowing or blocking any attempts to connect.

IS there any way of provisioning it within the LAN then moving it outside? Or some way to manually enter the settings needed to connect?
 
Make sure when you put in the server config path you are putting in the provisioning URL without the https:// since you've already selected HTTPS right above. Also make sure you've 'Unchecked disallow use outside of LAN' on that extension.
 
  • Like
Reactions: YiannisH_3CX
Thank you very much indeed for your help. Your final post has fixed it :)

You are correct to advise that "Make sure when you put in the server config path you are putting in the provisioning URL without the https:// since you've already selected HTTPS right above"

For future reference it might be helpful to mention that in the manual provisioning guide, since it does tell you to 'copy & paste' the link from when you set up the phone in management console. Or perhaps the system could parse the URL and strip out a 'double https:' if present.

Either way it's working so thanks again for your help :)
 
Glad to see the issue has been resolved and thank you for updating the thread with your solution.
 
Status
Not open for further replies.

Forum statistics

Threads
111,930
Messages
589,801
Members
164,803
Latest member
fcentral