Provision File cannot be reached

Status
Not open for further replies.

Reggie997

Forum User
Basic Certified
Joined
Mar 23, 2020
Messages
9
Reaction score
0
Hi Everyone.
The company i work for is having a slight problem. We are in the middle of a planned upgrade from v15.5 to v16, however we have changed a few things from one server to the other.
-We got have changed the external IP so that it exits the business on a different IP as all traffic. I've changed the external IP address that I need to.
-We have changed the FQDN as we have built our next server off a backup that had the old FQDN.

The problem we are facing is that we cannot provision our desk phones and our mobiles. We are able to provision our soft phones however and use them to call out no problem. We have opened the needed ports on our firewall so there shouldn't be anything being blocked. Also one thing to mention, we have changed from the default HTTPS (5001) to 443.
 
Hi Sorry hope this helps.
The version we are currently using is version 15.5 and we are upgrading to 16.0.504.
The server we are using for our new server is windows server 2016.
We host our PBX in house.
The phone i am trying to provision is a Yealink T41P (which does work as i use one for my desk phone, and one at home) & my mobile via QR code.

The provisioning method i am trying to use is Direct Sip - STUN.
Firewall has passed.
Custom Templates: No

Anything else please ask :)
 
So you are currently upgraded? First thing is basic troubleshooting. The phone inside the office should be using Local LAN unless I'm misunderstanding your network configuration so it should just be something like http://192.168.1.100:80/xxxxxxxxx/ . From home it would be https://3cxfqdn:443/xxxxxxxxxx/ . Do neither of them work? Can you access the 3CX management console internally (on the internal ip, no https) and externally?
 
Hi Sorry,
We are currently using v15.5 and are planning to upgrade to v16 once we are certain that everything works. But we have two servers, our main (v15.5) and out test (v16).
I have no way to check the in house desk phones as all of our offices have been closed, however i do have a mobile, laptop, and desk phone with me at home to play with.
The laptop seems to provision on the new server fine, however the mobile gets an error when i try to provision on the system ("Provision File cannot be reached"), and the deskphone just straight up doesn't do anything.
Currently i have it provisioned on our main server to make sure that i can connect to it from outside the network.

For the URL i am using theh https://voip.********.com/provision/*******
I am able to access the management console from outside & inside the network from both laptop and mobile.
 
Please note that if the external IP has changed, and the FQDN updated, it can take up to 6 hours on a Standard license for the DNS to resolve to the new IP.

The phones are probably resolving to the old IP. Wait a few hours and try again.
 
I am using a temp license that you get to trail the software. I don't want to make call but i want to make sure that i can get devices to connect.
The system has been online since Thursday last week, and still no go
 
Reggie you said you changed FQDN, HTTPS port, and external IP.

The only correct way to change FQDN and ports is during installation, with a backup that does not contain an FQDN, and a Key that has had its FQDN released from the Customer Portal. If this is not the way you did it, I would suggest to save yourself some time and start from scratch. If any parameters have been modified manually, I would expect issues.

Finally, the firewall ports should be open such that if you type the fqdn into a browser from an external internet connection (ie from your mobile phone over 4G -not wifi-) you should be able to reach the management console and log in. Once you log in, you should see the status showing the correct current external IP.

Make sure the above instructions have been carried out, and we should have positive results.
 
Hi,
When doing a backup i made sure to leave the license and FQDN behind on the old server, allowing us to move to our new FQDN and dns that we manage from our servers.

I can confirm that i can get to the management console via mobile on 4g, and it does show the correct external IP address that we want to use.

So all test are positive.
 
Oh side note. I am currently in the middle of a packet capture to see where the phone is trying to reach.
I will return with the test results
 
Good work, lets see if it reaches the correct machine.
 
Update.
So for some reason our provision link that we get from our new server is wrong.
while the URL does say voip.********.com/Etc/etc, the DNS assigned to that URL goes to our old server.
I've checked the customer portal and our DNS rules on our servers, and they all point to out new external IP and new server name...
 
Update Part 2
Did some more testing with wireshark.
So turns out the DNS problem fixed it self. Not sure how, as I've had this problem since Thrusday last week.
Now, the phone speaks to the server, the handshake goes through. But the it fails on the Certificate.

1585070709703.png

It's just strange, cause we never needed this on our old server. All i needed to do was upload the provisioning URL to the web interface, and reboot. But now... I don't know, I've tried uploading our cert to the phone but still no go.
 
AHh the old custom fqdn. Not sure why people insist on making life harder for themselves.


http://support.yealink.com/faq/faqInfo?id=13

Make sure you are uploading the CA certificate and not your certificate or just turn off the only trusted certificate option
 
Our supported devices will work with 3CX FQDN-issued certificates, they run off Let's Encrypt.

Your phones might not support the CA you are currently using, that can't be helped unless you do manual work as stated above.
 
Hi Guys.
So good new (sorta).

I did what cobaltit suggested and turned off the trusted certificate, and the phone provisioned right away.
As for the CA certificate needed, we have a certificate from SSL when we made the new server, and this is the cert that we inputted when we created the new PBX. I have the feeling that we are using the wrong one.

As for what JohnS_3CX said. I noticed that the Yealink T41P isn't in the list of phones but the T41S and the T41 are. I've used the T41P for months on our previous server (V15.5) with no issues when provisioning.
As stated before i pull across all configs from the old server leaving the old FQDN and license behind, so i should have the needed certs in the server for them to talk to one another without disabling Trusted Cert. (Right? I feel like I'm wrong, just not to sure).

We want to use these phones outside the network as we have employees across the UK (Scotland , Liverpool, etc) with trusted cert off, will that leave the phone vulnerable, or will it be safe to use?

Thanks for all your help, This has been a LONG two days troubleshooting this.
Hopefully we can go live with the upgrade on Friday, otherwise I'll have to explain why we can't (hope not) :) :)
 
Think of it this way: the phone is programmed by Yealink in their firmware to only trust certificates issued by certain authorities. If your cert was issued by any other authority than that, then the phone will consider it untrusted and cannot establish an HTTPS session with your server unless you upload your cert into the phone or disable trusted certs altogether. The link @cobaltit posted covered these aspects fully.

We use LE as an authority which is already trusted by the Yealink phones we support.

PS: the T41 = T41P and it is supported
 
Status
Not open for further replies.

Forum statistics

Threads
111,940
Messages
589,850
Members
164,831
Latest member
Michelle Waterson