Phones Appearing in 'Phones' Tab When Reset But Cannot Provision via SBC

Status
Not open for further replies.

Reece Cawthorn

Platinum Partner
Advanced Certified
Joined
Mar 5, 2021
Messages
58
Reaction score
15
Hi,

  • 3CX Version, Enterprise Annual 18.0
  • Is the 3CX Server Hosted and where: Hosted on Amazon Lightsail
  • IP Phone Make/Model/Firmware: Yealink T42S (66.86.0.5)
  • Provisioning Method: SBC version 18.1.36
  • Trunk Provider or Gateway Make/Model: Gamma
  • Has the Firewall Checker passed: YES
  • Are custom Phone Templates being used: NO

I am currently experiencing an issue with provisioning phones on a 3CX instance via SBC.

When reset, these phones do appear in Bold on the 'Phones' Tab of the Management Console (see below) but they cannot be assigned to the appropriate extension either by 'Assign Ext.' on the Phones Tab or by inputting the Provisioning Link into the backend of the device (both result in no change to the phone (Phone remains in bold on the Phones Tab and does not pull any Extension Information from the Server)).





Firewall wise, all ports for the SBC have been opened to allow all traffic to/from the server (including Ports: 5059, 5060 and 443) and the Firewall Checker passes without issue.

Please could anyone advise why this phone may not be provisioning? Or what to try next?

I look forward to hearing from you and please don't hesitate to let me know if you require any further information on this to work towards a resolution!

All the best,

Reece
 
Last edited by a moderator:
Hello Reece,

Firstly it should be noted that at the SBC site, no port forwards are necessary. Remove those in case you made any.

The second most important thing, is that the phones need to have full internet access. If you are blocking them from using the internet, they will not be able to reach the 3CX server to retrieve their provisioning file.

The third thing, is that your PBX side TLS port (5001 by default) must be reachable from the phones (and generally from the internet).

Finally, if you have issues with TLS (ie. certificates expired OR not compatible with Yealink) the phone will again try and fail.
 
Hi,

Thank you for getting back to me on this!

Unfortunately, I have confirmed all of the above with the customer's IT/Network Provider and the issue continues to persist.

I have also had the customer run a Ping Test from the telephone (8.8.8.8) and all packets were sent and received successfully (no packet loss).

However, a Ping Test to the Local IP of the SBC on-site Failed.

I have also attempted to change the SBC from TLS to TCP but this has not changed anything.

For additional information, this SBC is being ran on a Beelink U59 Business Mini PC Windows 11 Pro with Intel 11th Gen 4 Cores 8GB DDR4 256G SSD.

Do you have any additional advice to resolve this?
 
However, a Ping Test to the Local IP of the SBC on-site Failed.
If your phones and SBC cannot talk to each other, then the SBC will not be able to send the command to the phone so it can provision itself.

but they cannot be assigned to the appropriate extension either by 'Assign Ext.' on the Phones Tab or by inputting the Provisioning Link into the backend of the device
But you said that the phone does not provision even when done manually, where the SBC is not involved at all.


I think the only way to get to the bottom of this is to run a capture on one Yealink, and while running try to provision it manually using this method https://www.3cx.com/sip-phones/manually-provision-yealink/

After about a minute, you should end the capture and analyze it in Wireshark. This is the quickest path to finding out where the provisioning fails, and also whether you've missed something along the way (ie.DNS resolution failure, TLS handshake failure, Destination Unreachable).

Expected correct procedure:

  1. Phone does DNS lookup towards your FQDN
  2. DNS server replies with a valid IP
  3. Phone opens TCP connection to that IP
  4. TLS handshake takes place
  5. Application Data is exchanged
  6. Phone provisions itself and reboots

Find which step fails, make a correction, and check again.
 
From the sbc server can you ping ip address of one of the phones.

Pings maybe blocked due to firewall rules - SBC firewall is in private or public settings

If entering the provisioning url in the phone manually does not register the phone, can you access the 3cx management console on a device connected to the same lan as the phones.

Under options for the extension is this unticked.1656425784398.png

Check 3cx blacklist and remove any entries
 
Last edited:
I think the only way to get to the bottom of this is to run a capture on one Yealink, and while running try to provision it manually using this method https://www.3cx.com/sip-phones/manually-provision-yealink/

After about a minute, you should end the capture

I have asked the end user to test this on-site and received the following feedback:

"I couldn’t run the pcap as everytime I start it and click on provision now it would stop the capture automatically, so I could not get any logs from it."

Please could you advise whether this is expected? Or what needs to be changed in order to run this Packet Capture successfully?
 
Please could you advise whether this is expected?
Not expected, in my test I was able to get the capture so I'm not sure what to suggest beyond that. Perhaps if you have a switch with port mirroring, or the ability to capture from your main firewall at the site.

this SBC is being ran on a Beelink U59 Business Mini PC Windows 11 Pro
NOTE: Regardless of whether the phones end up provisioning or not, please note that Windows 11 for the SBC is unsupported. This should be changed to Windows 10 Pro or use our Debian ISO. I have no idea what will happen if you try using the SBC the way it is now so this is one thing you need to address for the overall "sanity check".

What else can you look for?

a) if the phones were previously configured as STUN, then they will show a prompt during startup, asking you to enter credentials. During this prompt, they will totally ignore any remote provisioning commands you send them - until the prompt is manually cancelled on the LCD screen of the phone

b) Whether you know about it or not, make 100% sure that the DHCP server at the phones site does not have Option 66 enabled. If phones find provisioning data via DHCP Options they might completely ignore your provisioning commands.

Hope this helps Reece!
 
  • Like
Reactions: accentlogic
Hi John,

Thank you for getting back to me on this - I appreciate the continued support!

I have been able to obtain the PCAP and have ran this through Wireshark.

The issue appears to be below:

1656495620869.png

Based on this, are there any suggestions you could make to resolve this issue? Or would you require any additional information/tests to resolve this?
 
This doesn't make any sense to me o_O

No sure what to suggest, I think it would be a good idea to open a case with 3CX Support and provide them with captures and logs so they can analyze them better.
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,284
Members
164,662
Latest member
DejanMDS