Solved Is Router Phone preferred over STUN for Single Remote Phone?

Status
Not open for further replies.

JustinB-PedEnt

Premier Customer
Joined
May 5, 2020
Messages
45
Reaction score
12
I have a small number of users who work from home. They have Yealink T46S phones provisioned as STUN. Is it now best practice to replace these with a T5x configured as a router phone? I assume the STUN configuration will keep working but it sounds like the SBC option may offer better performance and/or less risk of complications from their personal routers/firewalls.
 
STUN will keep working until it doesn't anymore.

But yes, I would swap those for router phones. Much better and encryption as a bonus.
 
but it sounds like the SBC option may offer better performance and/or less risk of complications from their personal routers/firewalls.
Absolutely yes.

The SBC phones will work much more reliably, even if the user changes their ISP, or their router or moves the phone elsewhere.

No port forwards required, no messing with router settings or calling up your ISP to disable things on the modem.
 
Thank you for your replies! I have deployed a T53W as a Router phone and confirmed it's working. Two observations I came across that I'm hoping someone can confirm for me:
  1. The guides I found recommend to set the phone up from the Webclient. This won't work if the user already has one phone (on-prem) configured, as I did not see the option to add an additional phone from that UI. I was able to follow steps using the Admin Console to complete the setup.
  2. The option for [Block Remote Phones using STUN (insecure!)] has to be unchecked. The other option for [Block Remote Tunnel/SBC Connections] sounded more relevant but without the STUN option enabled I receive a "Block WAN request is ON" warning in my dashboard when the phone attempts to register.
 
  • Like
Reactions: SteveITS
This won't work if the user already has one phone (on-prem) configured
Correct, per other posts from 3CX it needs to be the first phone for that user.

re: unblock STUN, I haven't had the opportunity to set one up yet. If that's really the case I'd wonder if it could be blocked after the router phone is set up... On one hand it does make sense because it isn't connecting through an SBC or local, but it's not in the doc page.
 
Thanks for the sanity check.
I'd wonder if it could be blocked after the router phone is set up...

Setting it back to block makes the phone revert to 'No Service' almost instantly. I spent some time toggling it on and off just to test the reaction time.
 
Thank you for your replies! I have deployed a T53W as a Router phone and confirmed it's working. Two observations I came across that I'm hoping someone can confirm for me:
  1. The guides I found recommend to set the phone up from the Webclient. This won't work if the user already has one phone (on-prem) configured, as I did not see the option to add an additional phone from that UI. I was able to follow steps using the Admin Console to complete the setup.
  2. The option for [Block Remote Phones using STUN (insecure!)] has to be unchecked. The other option for [Block Remote Tunnel/SBC Connections] sounded more relevant but without the STUN option enabled I receive a "Block WAN request is ON" warning in my dashboard when the phone attempts to register.

Hi Justin,

It sounds like you did not configure it correctly. Here is what I recommend doing in case you have 2 phones:

1. Factory reset both phones
2. Make sure they both have the correct firmware (important!)
3. Go to the Management Console - Delete both phones from the extension
3. Make sure the circled settings are exactly like my screenshot:
1675932881316.png
4. Now visit the webclient admin page and add the router phone first from there
5. Reboot the router phone so that it will ask for credentials
6. enter credentials and when the phone restarts, make sure calls work.

7. Now log into the 3CX Management Console and go to the Phones page (so we can do the 2nd on-prem phone)
8. You should see the 2nd on-prem phone in bold (confirm its the correct one via MAC)
9. Select it and press the "Assign. Ext." button, then pick the extension you want to assign it to and press ok
10. It will take you to the extension's provisioning tab, you just need to press ok and the on-prem phone will now also provision

You will now end up with both phones provisioned. Make a couple of test calls to confirm and you are done.
 
Hi John,
Thank you for the writeup. I'm trying to follow the steps but my T-53W router phone will not ask for credentials after a reboot. I have also re-flashed the 96.86.0.74 firmware.

The only prompts on the phone after a reboot are 'Obtaining IP Address', 'Config Updating', and 'Redirector - Update skipped' before it sits with a No Service warning.
 
The behavior you described usually happens if you a) enter a wrong MAC address or b) if your server has certs that the phone does not trust from the factory (linked here)

a) quickly check the MAC against the back of the phone

b) If using a custom FQDN paste your domain here and check what certs you are using or if you are maybe missing an intermediate certificate https://www.sslshopper.com/ssl-checker.html - If the problem is b) you will have to find a way to fix it before the Yealink can provision successfully.
 
  • Like
Reactions: JustinB-PedEnt
It turns out we are missing the intermediate cert. Thank you for catching that, I plan to correct it this evening and try again.

Just so I better understand how the remote provisioning works: Has Yealink/3cx set up some kind of public broker that the phones query to identify the correct provisioning URL based on MAC address? I haven't seen any documentation with the technical details of how the Router Phone provisioning works.
 
  • Like
Reactions: JohnS_3CX
  • Like
Reactions: JustinB-PedEnt
Thanks for the info and support.
After fixing our SSL Cert I followed the steps again and the Remote RPS provisioning worked as intended.
 
Status
Not open for further replies.

Members Online Now

No members online now.

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK