Yealink phones not working properly, other phones are

Status
Not open for further replies.

dmaynard71

Free User
Joined
Jun 13, 2018
Messages
18
Reaction score
4
Hello! I have a small 3cx PBX system that runs on Google Compute Engine. There are about a dozen extensions that use desk phones. About 6 weeks ago I began having problems with our 4 Yealink phones not working. The rest of the phones are Fanvil and all work without any issues. They are set up with STUN. All of the phones have worked flawlessly in the past for over a year and there were no known system changes that should affect anything they do.

Description of issue:

2x T23G, 1x T46S, 1x C960
The Yealink phones all show as registered in the 3CX dashboard, little green light and all. They normally would show the extension number and name of user in the upper left of the screen, but now just say "no service".The phones say "Invalid Account" when trying to dial a number. I'm not positive, but I think that a couple of the phones will connect properly every now and then, but stop working after a while. (The C960 is relatively new to the system, wouldn't connect at first, but is now humming along happily.)

What I've done:

Made sure firmware is up to date.
I have tried factory reset and re-provisioning, doesn't help.
I brought two of the phones home and plugged them in on my home network, They immediately got extension numbers and name and worked perfect. Took them back to the shop and got a big NOPE from them.
Ran firewall check on 3CX and all is well.
Read something about ALG being a possible culprit, but I think that is set as it's supposed to be. Again, I didn't change anything anyway and they worked before.

I really don't even know what to suspect at this point. Maybe 3CX updated and did something weird to just the Yealinks?

Any help? I'm at a loss.
 
Did you do a proper setup of STUN (unique SIP/RTP port ranges for each phone with forwarding at the firewall) or did you STUN and pray? I'm assuming the latter and that's the problem. Setup a SBC
 
  • Haha
Reactions: JohnS_3CX
Did you do a proper setup of STUN (unique SIP/RTP port ranges for each phone with forwarding at the firewall) or did you STUN and pray? I'm assuming the latter and that's the problem. Setup a SBC

Welp, didn't know there was any other way to do it! I find it weird that what I have would work for so long and all of a sudden flake out, but I am displaying my ignorance here, I guess.

Any chance you could point me in the right direction for doing what you have suggested, and if you have time, maybe a little of the reasoning behind your suggestion? Any help would be much appreciated.
 
It's not as well documented as it should be.Here is an older link with a notes at the bottom pertaining to multiple phones and port forwarding:

https://www.3cx.com/docs/manual/configuring-ip-phones/#h.ul2fzupi6t22/

Long story short there are some routers that absolutely won't work at all without the port forwarding, and then some that work for a while and then fall down. But if you want it bulletproof, you need to configure a unique SIP port and RTP port range for each device and the forward to the phone using a static IP or DHCP reservation to make sure it stays on that IP. It's an administrative nightmare so the general rule of thumb is for more than 1-2 phones to use a SBC.

For 12 phones you can use a Raspberry Pi if you don't have an available PC or VM onsite. Do note you need to get a Pi 3 as the 4 is not supported yet.

https://www.3cx.com/docs/3cx-tunnel-session-border-controller/
 
  • Like
Reactions: AWS2P
Am I understanding correctly?

Option 1) I could fuss with configuring SIP and RTP and Static IPs
or
Option 2) Install a SBC on a local machine (VM is doable for me)

Alternately, would simply moving the 3CX server on site be an easier fix? If yes, will a VM with a dedicated NIC be ok, or should I have a dedicated computer/Pi?
 
Option 1 and 2 both work, with Option 2 being my preference every time in your situation. Moving 3CX in-house is also an option which would make life easier as well, but you lose the survivability of the cloud. For most companies even if the internet is down if folks can still reach IVR/VM and leave messages, especially with VM to email they are ok with not actually being able to make calls.
 
  • Like
Reactions: JohnS_3CX
Stun setup with difference sip , rtp ports applies to all phones setup with stun, so you should do the same for fanvil phones

for the amount of phones, go down the sbc server route
 
Last edited:
  • Like
Reactions: JohnS_3CX
I think your initial test proved that the phones were properly provisioned and could register to the PBX.

The only likely thing standing between them now is your firewall/access. An SBC should take care of things for now. Just remove the phones from the extensions, reset the devices, and reprovision them as soon as they appear in the phones section via the SBC
 
The only likely thing standing between them now is your firewall/access.

That was where my thinking was headed, but I'm still lost as to why they would work find for so long and then quit. IP's changing or something? They are on DHCP right now. Doesn't really explain why just Yealink though.

Maybe I will never understand. That's ok, I'm just curious.
 
It was explained on post #4 by @cobaltit It's a rather mundane and simple explanation, you are relying on your router/firewall to take care of opening and closing ports according to whatever it thinks is the best way (tip: it's rarely smart enough to do so). The way it behaves may not be consistent or we may simply not know how the internal code of that device makes the decision to open/close/redirect ports. Given a myriad of manufacturers and hardware and firmware revisions of these devices I would say it's effectively unpredictable from a practicality standpoint.

So to be on the safe side, assume the worst, plan for the best.This is why we recommend to open the ports manually, it's a way to force the device to keep the specific ports needed by each specific phone open. It will make sure that phone-A will always get IP-A (based on it MAC address) and will always be assigned ports-A. Same for phone B, C and so on. With a handful of phones it may be manageable to keep reliable connections open for your phones but the more you add the more administration is necessary on your part (set individual ports on 3CX provisioning, set static IPs on the phones side router, set SIP and RTP ports on the phones side router).

An SBC reduces the need for doing the above:

  • Easy phone provisioning
  • No ports to worry about
  • Encryption comes as standard
  • Has cool stats to see on your dashboard :)
  • You can disable "PBX Delivers audio" on extensions VS STUN that requires this and save some bandwidth and latency on local EXT calls
  • Can even run on a Raspberry Pi
 
Thank you for all of your input! I have the phones working now, but still plan to implement the SBC.
 
  • Like
Reactions: JohnS_3CX
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,934
Messages
589,822
Members
164,813
Latest member
divdigital