SRTP not working with Yealink T46S

Status
Not open for further replies.

cwidmer62

Joined
Dec 1, 2015
Messages
9
Reaction score
1
We use SRTP and with the "G"-series of the Yealink phones this works well (SRTP = compulsory). I use a self-signed certificate and everything is updated to the newest version (3CX-PBX, phone FW, template). Signalling is TLS.

Now, with a Yealink T46S SRTP does not work. Upon calling another extension with the T46S, the destination is ringing, but when the phone is picked up, an error message appears "outgoing call not possible). When I call the T46S from another extension, the same error message appears directly, without ringing.
The 3CX-PBX logs the following error message (calling extension 316 from the T46S):

09/03/2018 7:23:01 AM - Exception: ParseException E:\jenkins\workspace\15.5SP6\SPBuild\Sources\3rdParty\Resiprocate\rutil/ParseBuffer.hxx:230, Parse failed unexpected eof in context: 316 ^ @ E:\jenkins\workspace\15.5SP6\SPBuild\Sources\3rdParty\Resiprocate\rutil/ParseBuffer.hxx:230

[The 3CX is on drive C: on Windows (10-1803), there is actually no drive E: on the 3CX-Machine.]

Are there any ideas why this is happening?

Thanks

Christoph
 
And what happens if you try and traverse this location ? nothing I imagine ?

What firmware is running on the Yealinks ? is it up to date as per the 3CX guidelines ?

NOTE: If you enable SRTP, then you should also enable TLS. This ensures the security of SRTP encryption.
 
And what happens if you try and traverse this location ? nothing I imagine ?

What firmware is running on the Yealinks ? is it up to date as per the 3CX guidelines ?

NOTE: If you enable SRTP, then you should also enable TLS. This ensures the security of SRTP encryption.

Thanks for your reply.

The firmware of the Yealinks is up to date (66.83.0.20 for the 46S that's having the issue).
Yes, I'm using TLS.

I'm not quite sure I understand what you mean by "traverse this location".
To explain a bit further, I'm currently testing TLS+SRTP internally, so the common name of my certificate is the internal IP address. From externally I would either have to tunnel or use another certificate with the external URL. That being said, I don't think it is a certificate issue as a number of Yealink G-Series phones (T48G, T46G and T42G) are all working with the same setup.

For now I only have a Yealink T46S from the S-Series to test, but I really cannot get this phone to work with TLS+SRTP (but only the SRTP portion is not working, TLS + SRTP = optional works).

Ultimately, my idea is to use TLS+SRTP for the external phones, inside my own LAN this is not strictly required and probably a bit overdone. But I wanted to test everything first, so I use the internal setup for now.

Best regards

Christoph
 
Hello @cwidmer62

Please note that the error you are getting is not related to the issue you are facing. It is a developer part that has nothing to do with your machine so you can safely ignore it.

I have tried the scenario with an Yealink T46s and it works for me. Make sure that the phone is configured correctly and the correct port is used under the account settings. Also SRTP also has to be enabled through the phones web interface.
 
Hello @cwidmer62

Please note that the error you are getting is not related to the issue you are facing. It is a developer part that has nothing to do with your machine so you can safely ignore it.

I have tried the scenario with an Yealink T46s and it works for me. Make sure that the phone is configured correctly and the correct port is used under the account settings. Also SRTP also has to be enabled through the phones web interface.


Thanks for the info on the error message. Unfortunattely I'm still stuck with G-series working and S-series throwing an error.

You mention, that "SRTP also has to be enabled through the phones web interface".
I only found the setting for each account under "Account" --> "Advanced" --> "RTP Encryption (SRTP) = Disabled, Optional, Compulsory.
Is there any other place in the Yealink S-series where SRTP has to be enabled?

Thanks for your help and best regards

Christoph
 
I only found the setting for each account under "Account" --> "Advanced" --> "RTP Encryption (SRTP) = Disabled, Optional, Compulsory.
Is there any other place in the Yealink S-series where SRTP has to be enabled?
That is the option i suggested for SRTP. Since that is correctly configured and you changed the port to 5061 in the registrar then it should work. Since the other phones are working it would suggest a configuration error somewhere. Try resetting the phone and re-provision it to see if that helps with the issue.
 
That is the option i suggested for SRTP. Since that is correctly configured and you changed the port to 5061 in the registrar then it should work. Since the other phones are working it would suggest a configuration error somewhere. Try resetting the phone and re-provision it to see if that helps with the issue.

Hi,
thank again for your message.

I have continued to tinker with this in the meantime. I can report now, what I found out:

My 3CX installation is not a fresh install with 15.5 SP6, but has been updated several times, and is now on SP6.
When I provision a G-series Yealink phone to an existing (i.e. created pre-SP6) extension, it works (always meaning TLS+SRTP).
Provisioning an G-series phone to a newly created extension does not work since updating to SP6.
Provisioning an S-series phone never works, not on a new nor on an existing extension.

The error thrown "E:\jenkins ....." is a real error, it always appears when the connection is refused.

IMHO there is some glitch in the 3CX-PBX with this.
This is as far as I can get and I will abandon the issue for now. You might wish to forward this information to the developers.

Thanks for your consideration and kind regards

Christoph
 
Thank you for the update and the added information. I will further look into this and see if i can replicate the issue.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,893
Messages
589,598
Members
164,763
Latest member
Techmansam