How To: One-Off Support for Remote and/or Ancient SIP Phones + siproxd

Status
Not open for further replies.

caldwell

Bronze Partner
Basic Certified
Joined
Nov 8, 2010
Messages
97
Reaction score
28
Having recently gone through the latest Beginner and Advanced training with Nick, I was inspired to take up the challenge of connecting a Yealink SIP-T28P to 3CX. Occasionally, you may have a remote user who needs to connect to your 3CX PBX but don't have a case for running an SBC. The problem with attempting to just install the phone without a proxy is that the SIP packets will contain the private (192.168.x.x and such) address in the header. 3CX doesn't know how to route across the Internet back to the private address. However, if you can install a firewall such as pfSense (free) and the siproxd package on that system at the remote user's home/network, you can still make it work.

The basic configuration of the old Yealink phones is explained here:
https://www.3cx.com/sip-phones/yealink-t20p-t22p-t26p-t28p/

Essentially, for older or unsupported SIP phones, you need to configure the phone manually on 3CX. Some users have reported being able to pull a template from a "nearby and still supported" Yealink phone model. YMMV. The main points in the above doc are to note that the Register Name is the jumbled/cryptic random string 3CX sets for the user, the User Name is the Extension Number, and the Password is what 3CX assigns to the user.

Then, install the siproxd package on pfSense. Enable it. Most of the default settings shown below should be sufficient for your purposes. However, note that you need to change the RTP Port Range (Lower) and RTP Port Range (Upper) to 9000 and 10999 to match 3CX audio ports!

View attachment 1723816169402.png


Make sure that your pfSense is set to use Manual Outbound NAT:

pfSense siproxd NAT.png


Go to your IP phone and add the account settings from 3CX. Set your Display Name and other settings to suit you.

Look for the section on Outbound Proxy and enter the IP of your firewall. Be sure the port matches the siproxd port. Enable the Outbound Proxy.


Yealink siproxd.png


After you have configured and saved everything, your phone still may not work. Why? Remember that little mention in training about security and blocking remote connections? Yep. That's it. Go to your User, Options, and look for "Block remote non-tunnel connections" and uncheck that. Save. Your phone should now be registered.

3CX siproxd.png


Of course, if you find that you have a growing number of users, installing a dedicated solution will be easier to support long term. Hopefully this helps someone.
 
Last edited:
Occasionally, you may have a remote user who needs to connect to your 3CX PBX but don't have a case for running an SBC.

I think you may have just achieved the opposite, and made a case as to why you actually do need to run an SBC:

- No port management required on firewall
- No port config required on phone
- No additional packages to install on firewall
- No issues with private IPs
- No always exposed ports to the internet
- No need to enable risky extension options
- No one-way audio issues*
- No registration issues*



Meanwhile, SBC extra benefits beyond not having to deal or maintain the above:

- You get TLS encryption between PBX and SBC
- It can work even with EOL phones you manually configure
- You can add more phones if needed later
- RTP traffic of phones behind a common SBC does not need to go over the internet
- Your installation remains support-eligible in case you need to contact 3CX Support
- Some phone models have a built-in SBC in the firmware (all in one solution)

One may wonder, why not replace the aging T28P with a newer device that can act as a standalone router phone for that single remote user? ie. Yealink T42U
 
Last edited:
  • Like
Reactions: Evolute IT
These are all excellent points, none to be ignored.

My response would be that there are geeks out there who would find the ability to do this useful. I also have done VOIP projects in developing countries, and this type of solution may be useful as a one-off in those locations.

As to the question of "why not replace the old phone with a newer one," the reality in developing countries is that sometimes they may be gifted older phones from US or European companies which are still adequate for general purposes, or they may not have ANY budget for replacing infrastructure. I work with such organizations on a routine basis.

Please note: the post started with me being inspired to take up the challenge of getting an older phone connected "as-is." I didn't say, "This is the best solution" or even the preferred solution. An SBC is superior in many respects. I just wanted to provide a documentation for people who may find themselves in such a situation that they need to do this, perhaps quickly.

[I still remember various analog modem "AT" command strings. They are not used almost anywhere by the majority of people. But I still see analog modems connected as backdoor devices into corporate firewalls and routers "just in case." So, remembering about modems is useful to those people.]
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,939
Messages
589,843
Members
164,824
Latest member
Xeniosg