TLS transport for Yealink Remote Phones

Status
Not open for further replies.

criffus

Customer
Joined
Jul 29, 2019
Messages
2
Reaction score
0
Hi,
I hope this issue isn't already solved or discussed in-depth in another thread.

I have a basic 3CX installation running on LightSail (v16) for a small office with 5 extensions. (Yealink T46S, T41S, W52P) (No SBC)

All 5 phones/extensions were working perfectly until I had to power cycle the PoE switch they are attached to. Afterward, only 2 phones would register successfully. The problematic phones all seemed to be in a state of perpetual registering as best I could tell from their respective local web interfaces. I troubleshot this for quite a while and tried to dig up some answers here in 3CX forums as well as other resources. I tried removing phones all-together and reinstalling, etc. No luck though.

As a last "shot in the dark" I went ahead and changed the SIP transport from UDP to TLS and it worked.

My question then is "why"? My VoIP knowledge is not only rusty but also nowhere-near expert to begin with. I'd like to make an informed decision though, on whether I want to mess around with templates in order to attempt to make my choice of TLS persistent in the configurations. Or, if I need to make some other changes in my implementation.

Thanks

*I am running the latest firmware on all phones, downloaded directly from 3CX.
 
Hi,
I hope this issue isn't already solved or discussed in-depth in another thread.

I have a basic 3CX installation running on LightSail (v16) for a small office with 5 extensions. (Yealink T46S, T41S, W52P) (No SBC)

All 5 phones/extensions were working perfectly until I had to power cycle the PoE switch they are attached to. Afterward, only 2 phones would register successfully. The problematic phones all seemed to be in a state of perpetual registering as best I could tell from their respective local web interfaces. I troubleshot this for quite a while and tried to dig up some answers here in 3CX forums as well as other resources. I tried removing phones all-together and reinstalling, etc. No luck though.

As a last "shot in the dark" I went ahead and changed the SIP transport from UDP to TLS and it worked.

My question then is "why"? My VoIP knowledge is not only rusty but also nowhere-near expert to begin with. I'd like to make an informed decision though, on whether I want to mess around with templates in order to attempt to make my choice of TLS persistent in the configurations. Or, if I need to make some other changes in my implementation.

Thanks

*I am running the latest firmware on all phones, downloaded directly from 3CX.
SIP TLS is not supported by 3CX at the moment. While it may work, it is not recommended. Please use UDP.

TLS transport shouldn't even work unless you used port 5061 on SIP Server Port. UDP and TCP uses 5060.

By the way, 5 extensions in STUN is not recommended, I would use an SBC for better reliability.
 
  • Like
Reactions: criffus
SIP TLS is not supported by 3CX at the moment. While it may work, it is not recommended. Please use UDP.

TLS transport shouldn't even work unless you used port 5061 on SIP Server Port. UDP and TCP uses 5060.

By the way, 5 extensions in STUN is not recommended, I would use an SBC for better reliability.
Thanks Frederick.

I assume I'll need to run the SBC locally here at the office using Raspberry Pi or something similar(?).
I had wanted to keep my implementation simple as possible, but from what I can gather, the SBC is the way to go for a number of reasons.
I haven't reviewed the process for configuring the SBC yet, but can I assume it's relatively simple? Or, rather, I won't have to do much with it after it's configured, and then I'll still manage 3CX from my LightSail instance?
 
Thanks Frederick.

I assume I'll need to run the SBC locally here at the office using Raspberry Pi or something similar(?).
I had wanted to keep my implementation simple as possible, but from what I can gather, the SBC is the way to go for a number of reasons.
I haven't reviewed the process for configuring the SBC yet, but can I assume it's relatively simple? Or, rather, I won't have to do much with it after it's configured, and then I'll still manage 3CX from my LightSail instance?
Yes, the SBC is really easy to set up in v16. A Raspberry Pi would be perfect for your needs (make sure to use the Pi 3B+).

And yes, you'll still manage the 3CX from the same place.
 
  • Like
Reactions: criffus
Hi @criffus

If you follow our guide you should be able to setup your SBC fairly quickly, and avoid some of the hassle with NAT traversal and port setup for each phone. https://www.3cx.com/docs/installing-pbx-raspberry-pi/

Use a Pi 3B+ and the image we link in our guide, and at the end of the page follow the next link to take you to the SBC guide.

You will have to change the provisioning method of each extension's device to SBC, including the DECT device you have, and then allow the devices to reprovision as soon as they reboot. The SBC is managed through the management console and so are the phones.
 
You can also use a windows machine as SBC too, if you are not linux familiar and want to be in known world with Windows ;)
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
111,933
Messages
589,811
Members
164,808
Latest member
jsbjsb