• We do not provide troubleshooting help for unsupported phones. Please try with a supported phone.
  • V20 Update 10 Alpha 2 Learn more

Provisioning cisco spa504g

Status
Not open for further replies.

ZenMasta

Customer
Joined
Mar 10, 2010
Messages
254
Reaction score
10
I know these are outdated. But I'm just trying to see if this thing still works so maybe I can give it away or sell it on the used market.
The current firmware is 7.6.1

I followed the easy instructions but no luck
https://www.3cx.com/sip-phones/cisco-spa/

It was provisioned back in the day, and when I turned it on, I could see my old blf's and stuff. But it didn't work of course because our ip/provision URL changed between then and now.

DHCP 66 is setup on our router as well as option 77 exclusively for the cisco (I added option 77 on the cisco phone before 66).
But even if this dhcp wasn't setup, manually entering provision URL in the provisioning tab> Profile Rule: should be sufficient.
I also noticed that a new cfg isn't generated in my provisioning directory, but then again I don't see configs for my yealink phones and those auto provisioned in the past just fine. I don't want to test my luck and nuke a phone for the sake of testing just in case I jinx myself though.

http://myip:5000/provisioning/mle3e9lbnz/$MA.xml

/var/lib/3cxpbx/Instance1/Data/Http/Interface/provisioning/ole7e5lpbg
If I try to visit the provisioning url manually to download a file that does exist, for example phonebook.xml I get this browser error

Secure Connection Failed

An error occurred during a connection to fqdm.3cx.us:5000. SSL received a record that exceeded the maximum permissible length.

Error code: SSL_ERROR_RX_RECORD_TOO_LONG

The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
Please contact the website owners to inform them of this problem.
 
Thanks. Similar to that guy, the last time I remember it working was on 15 or 16 as well.
 
So I'm curious because you seem to be trying to use HTTP based on your port and url example yet you are getting an error message with regards to SSL which shouldn't happen on the HTTP port.

Is this an on-premise PBX?
 
We have about 40 SPA504G at one of our client's. The system was originally setup on v16 and is currently updated to v18. All good, but the provisioning can be twitchy if the 504G already has a config setup. I found I had to reset the phone to factory default then reboot and let it auto-provision. Once provisioned everything is fine from that point on.

We use DHCP option 66. Need to take careful note of the provisioning link from the 3CX admin console (under phone provisioning). Firmware on the 504G is 7.6.1

The only reason they are using these Cisco phones is because they already had them from a previous PBX.

Hope this helps
 
So I'm curious because you seem to be trying to use HTTP based on your port and url example yet you are getting an error message with regards to SSL which shouldn't happen on the HTTP port.

Is this an on-premise PBX?
We are hosting remotely with digital ocean. Good catch there. Firefox seems to force https... but oddly enough, when I try firefox but with a private tab, it just says nginx 403 forbidden which I presume is just a result of my local pc's mac not being in the provision list.

I'll have to contact my server admin and see if there is some auto-switch from http to https because I know I am using the correct url. I will report back.

BTW, correct me if I'm wrong. As it's been a super long time since we used these. But I thought that these spa phones can't use https, which is why I am using http in the provision url.
If I switch to https and change the port accordingly, then I can view the config in a browser.

And in testing, if I manually put the https URL in the provisioning tab>profile rule text box on the phone, it still doesn't provision. I tried with the mac typed out vs $MA.xml
 
Last edited:
SPA phones are only supported locally:

1657045501260.png

If you turn off the TLS 1.2 setting in 3CX and play with loading a trusted root or turning off certificate verification in the phones manually before trying to provision it 'may' work although I don't know if you can do either with those phones. There's some other hacks you can try as well but generally it's not worth the effort unless you are talking a LOT of phones.
 
Status
Not open for further replies.

Forum statistics

Threads
112,148
Messages
590,963
Members
165,169
Latest member
Isaac415