- Joined
- Sep 13, 2019
- Messages
- 40
- Reaction score
- 15
Due to COVID-19 many of our employees are working from their home offices where it'd be impractical to deploy an SBC. The best solution is "Direct SIP (STUN Remote)". The catch is that all SIP signaling and RTP audio is sent in the clear for anyone to intercept.
It's trivial to create a custom template for Yealink T4x that sets the phone to use SIP over TLS (SIPS) and SRTP. What I would really like is built-in template support.
I have attached my custom template to this post if anyone is interested in using it. All non-cosmetic changes are commented with "SecureMod". The template uses a y-file index of 5, make sure you don't have a conflicting template. The template assumes that the phone is being provisioned via RPS and has been reset to factory defaults.
Read this before using it:
https://www.3cx.com/docs/custom-ip-phone-templates/
Your 3CX server should already be TLS enabled with a valid certificate signed by a public CA e.g. Let's Encrypt.
You will need to enable SRTP under "3CX App" provisioning for the extension, "Normal" RTP Mode will cause call failure:
RTP Mode: "Only Secure" or "Allow Secure"
IMO, the best settings to use under "3CX App" extension provisioning:
SIP Transport: TLS
RTP Mode: "Only Secure"
Unchecked "Use 3CX Tunnel for remote connections (3CX App only)"
Under extension options: Unchecked "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)"
I have tested the custom template with a Yealink SIP-T46S and a SIP-T48S. You may have to factory reset the phone to clear out the settings this custom template modifies. Use at your own risk.
It's trivial to create a custom template for Yealink T4x that sets the phone to use SIP over TLS (SIPS) and SRTP. What I would really like is built-in template support.
I have attached my custom template to this post if anyone is interested in using it. All non-cosmetic changes are commented with "SecureMod". The template uses a y-file index of 5, make sure you don't have a conflicting template. The template assumes that the phone is being provisioned via RPS and has been reset to factory defaults.
Read this before using it:
https://www.3cx.com/docs/custom-ip-phone-templates/
Your 3CX server should already be TLS enabled with a valid certificate signed by a public CA e.g. Let's Encrypt.
You will need to enable SRTP under "3CX App" provisioning for the extension, "Normal" RTP Mode will cause call failure:
RTP Mode: "Only Secure" or "Allow Secure"
IMO, the best settings to use under "3CX App" extension provisioning:
SIP Transport: TLS
RTP Mode: "Only Secure"
Unchecked "Use 3CX Tunnel for remote connections (3CX App only)"
Under extension options: Unchecked "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)"
I have tested the custom template with a Yealink SIP-T46S and a SIP-T48S. You may have to factory reset the phone to clear out the settings this custom template modifies. Use at your own risk.