Solved Phone not provisioned behind SBC

Status
Not open for further replies.

sistema_

Forum User
Advanced Certified
Joined
Dec 12, 2019
Messages
3
Reaction score
1
HI,

I hope you can help me with this problem:

I have a 3cx hosted PBX and a local SBC.

Behind my SBC I have two yealink phones with recommended firmware, i see them on my gui with IP

"local_phone_IP:5059 via SBC local_SBC_IP:5060"

but if I factory reset the phones and assign to an ext with pnp nothing happens.

I have a Fritzbox router operating as a firewall and I already have forwarded this ports:

5001 TCP
5090 TCP/UDP

My SBC does not have any restriction towards internet.

Thanks
 
Please note that you do not need to forward any ports to your SBC so close those.

Make sure the SBC can get OUT on 5001 and 5090

Can you provide more info on your SBC? What it's sitting on? Version? OS?

How are your phones and SBC connected?

Do you have a fancy switch that can manipulate multicast?

Model of Yealink? Current FW version?

Does your 3CX PBX pass the firewall test?
 
  • Like
Reactions: NickD_3CX
In addition to what @kieferschild mentioned, note that PnP provisioning via an SBC requires that the 3CX PBX can send a message to the IP Phone(s) via the 3CX SBC to instruct them to download the provisioning file over https (default port:5001). That said, please try provisioning the devices using the manual link provisioning method so that we can narrow down the cause of the issue depending on what happens.

Here is the guide for Yealink devices: https://www.3cx.com/sip-phones/manually-provision-yealink/
Note: During step 5, remember to select SBC as the provisioning method and to enter the SBC's local IP address.
 
Hi,

@kieferschild
SBC is installed on Qnap dedicated linux virtual machine, version 16.2.24
SBC has no outbound limitations
The phones and the SBC are on the same LAN
The switch device is a meraki MS120-8LP with no special rule defined
Yealink T28P 2.73.0.60
Firewall test passed

should I close port 5090 TCP/UDP? Reading the documentation seems to be a mandatory requirement for SBC

@ChrisC_3CX

I have two yealink devices, one T27G that provisiones correctly and a T28P that does not.
Also manual prov does not work.

in the "phones" section I can see:

192.168.x.y:5059 via SBC 192.168.x.x:5060 --> not provisioned
192.168.x.z:5060 via SBC 192.168.x.x:5060 --> provisioned
 
Regarding the ports, there may have been a misunderstanding. If you have forwarded those ports on the 3CX PBX end and not the 3CX SBC then it should be fine, they are indeed required and must be forwarded to the 3CX PBX.

Regarding the issue, do bear in mind that the T28P is an EoL model and, as mentioned in our guide, it is not compatible with 3CX's security setting on "SSL Transport and Ciphers". Access the 3CX Management Console, navigate to "Settings >> Security" scroll down to the end and make sure that " Enable PCI compliance SSL/SecureSIP..." is disabled, then try p[provisioning it again.
 
I've got the same issue but for the T46G.
To fix this issue I disabled the option at "Settings > Anti-Hacking > SecuritSSL/SecureSIP Transport and Ciphers" and updated the phone to the latest firmware of 3CX.
https://www.3cx.com/support/phone-firmwares/
 
  • Love
Reactions: CarAnalogy
Thank you.

In my case unchecking the option

"Enable PCI compliance SSL/SecureSIP Transport and Ciphers (This will leave only TLSv1.2 enabled and may prevent old legacy phones and old 3CX Apps to connect remotely to your system)"

in the security page, does the trick.
 
  • Love
Reactions: CarAnalogy
@sistema_
Glad to hear you got this resolved!

@Wesley Telecomlijn
The T46G does not require that setting to be off so you should've been able to provision it regardless.
Here are some quick troubleshooting tests:
1. Make sure you have followed our guide here: https://www.3cx.com/sip-phones/yealink-t4-series/
2. Make sure you can resolve the FQDN from the same site the IP Phone is.
3. Make sure you can access the Management Console on HTTPS port (default: TCP 5001) from the same site the IP Phone is.
4. If using a custom FQDN, make sure the IP Phone trusts the Certificate Authority. You might want to consult the vendors documentation about this.
5. If the issue persists try using the manual link provisioning method explained here: https://www.3cx.com/sip-phones/manually-provision-yealink/
Submit a new forum post and let us know what happened.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,835
Messages
589,289
Members
164,666
Latest member
infinititravels